Cortex XDR - Incidents connector for Microsoft Sentinel

Custom Data connector from DEFEND to utilise the Cortex API to ingest incidents from Cortex XDR platform into Microsoft Sentinel.

Connector attributes

Connector attribute Description
Log Analytics table(s) {{graphQueriesTableName}}
Data collection rules support Not currently supported
Supported by DEFEND Ltd.

Query samples

All Cortex XDR Incidents

{{graphQueriesTableName}}

| sort by TimeGenerated desc

Prerequisites

To integrate with Cortex XDR - Incidents make sure you have:

Vendor installation instructions

Enable Cortex XDR API

Connect Cortex XDR to Microsoft Sentinel via Cortex API to process Cortex Incidents.

Next steps

For more information, go to the related solution in the Azure Marketplace.