Zero Networks Segment Audit connector for Microsoft Sentinel

The Zero Networks Segment Audit data connector provides the capability to ingest Zero Networks Audit events into Microsoft Sentinel through the REST API. This data connector uses Microsoft Sentinel native polling capability.

Connector attributes

Connector attribute Description
Log Analytics table(s) {{graphQueriesTableName}}
Data collection rules support Not currently supported
Supported by Zero Networks

Query samples

All Zero Networks Segment Audit events

{{graphQueriesTableName}}

| sort by TimeGenerated desc

Prerequisites

To integrate with Zero Networks Segment Audit make sure you have:

  • Zero Networks API Token: ZeroNetworksAPIToken is required for REST API. See the API Guide and follow the instructions for obtaining credentials.

Vendor installation instructions

Connect Zero Networks to Microsoft Sentinel

Enable Zero Networks audit Logs.

Next steps

For more information, go to the related solution in the Azure Marketplace.