logo

NJP

Microsoft Azure Sentinel Incident Ingestion Integration For Security Operations

Microsoft Azure Sentinel Incident Ingestion Integration For Security Operations

by Service-now.com

Create Security Incidents automatically from Microsoft Azure Sentinel API incidents.

0 installs 0 reviews v11.2.3 Scoped Application Free (integration tables[10] not counted) 10 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 213 -213
151 days of no change
2025-11-26 212 +1
2025-11-25 211 +1
17 days of no change
2025-11-07 210 +1
3 days of no change
2025-11-03 209 +1
3 days of no change
2025-10-30 208 +1
6 days of no change
2025-10-23 207 +1
2025-10-22 206 +1
8 days of no change
2025-10-13 205 +1
7 days of no change
2025-10-05 204 +1
16 days of no change
2025-09-18 203 +1
2025-09-17 201 +2
7 days of no change
2025-09-09 200 +1
1 days of no change
2025-09-07 199 +1
2 days of no change
2025-09-04 198 +1
1 days of no change
2025-09-02 197 +1
1 days of no change
2025-08-31 196 +1
14 days of no change
2025-08-16 195 +1
1 days of no change
2025-08-14 194 +1
1 days of no change
2025-08-12 192 +2
7 days of no change
2025-08-04 191 +1
13 days of no change
2025-07-21 190 +1
2 days of no change
2025-07-18 189 +1
14 days of no change
2025-07-03 188 +1
2025-07-02 187 +1
21 days of no change
2025-06-10 186 +1
18 days of no change
2025-05-22 185 +1
7 days of no change
2025-05-14 184 +1
3 days of no change
2025-05-10 183 +1
9 days of no change
2025-04-30 182 +1
1 days of no change
2025-04-28 181 +1
2 days of no change
2025-04-25 179 +2
2025-04-24 178 +1
8 days of no change
2025-04-15 177 +1
20 days of no change
2025-03-25 175 +2
6 days of no change
2025-03-18 174 +1
5 days of no change
2025-03-12 173 +1
5 days of no change
2025-03-06 172 +1
2025-03-05 171 +1
5 days of no change
2025-02-27 170 +1
2 days of no change
2025-02-24 169 +1
12 days of no change
2025-02-11 168 +1
2025-02-10 167 +1
3 days of no change
2025-02-06 166 +1
3 days of no change
2025-02-02 165 +1
5 days of no change
2025-01-27 164 +1
9 days of no change
2025-01-17 163 +1
6 days of no change
2025-01-10 162 +1
7 days of no change
2025-01-02 161 +1
63 days of no change
2024-10-30 148 +13

About

The Microsoft Azure Sentinel Incident Ingestion integration allows you to automatically retrieve incidents from Azure Sentinel, convert them into security incidents, and enable automated response actions.

Key Features

This integration includes the following key features:

- Discover Microsoft Azure Sentinel incidents that are candidates for security incidents and automate the creation of security incidents.
- Mapping Microsoft Azure Sentinel incident and entity fields to SIR security incident fields.
- Filtering of Microsoft Azure Sentinel incidents.
- Aggregation of similar incidents to existing open security incidents so that you don't have to create duplicate security incidents.
- Automatic Microsoft Azure Sentinel incident status update for SIR security incident creation and closure.
- Scheduled ingestion of incidents that create security incidents periodically.
- Synchronization of Microsoft Azure Sentinel incident comments with SIR worknotes.

Version History (10)
v11.2.3 2026-05-05 14:59:08
Fixed: Access issues for Security Analyst on querying tables.
v11.2.2 2026-04-09 15:25:03
Fixed :  Fixed SIR creation issue from SIEM ingestion caused by missing Crypto module access for Secure Notes post Yokohama upgrade (Module A...
v11.2.1 2026-03-12 16:12:15
Fixed: Observable ingestion to validate successful insert before creating M2M task-observable relationships, preventing orphaned records when obse...
v11.2.0 2025-12-11 13:43:00
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v11.1.0 2025-07-31 15:36:24
New: Enabling users with "sn_si.ingestion_profile_admin" role to manage ingestion profiles on Azure Integration. Fixed: Category field in Azure ...
v11.0.26 2025-07-10 14:57:43
Changed: Introduced support for polling closed incidents during ongoing ingestion processes. Additionally, a new state field has been ad...
v11.0.25 2025-06-06 01:20:22
Fixed: AzureSentinelCommentStatusSync script include throwing "String object has exceeded maximum permitted size of 33554432" error. Empty SIR's g...
v11.0.24 2025-05-01 18:55:38
Changed: Introduced support for polling closed incidents during ongoing ingestion processes. Additionally, a new state field has been added to the...
v11.0.22 2025-01-30 15:19:20
Fixed: These defects are fixed:- Techniques is missing from Azure Sentinel payload Only supports single alert link in the SIR work notes and getti...
v11.0.21 2024-09-10 14:27:21
Fixed: In case of unterminated literal in response from sentinel, alert and entities creation is handled. Synchronization issue between SIR and Mi...
ID: 2e79ad6cfe4220103a962200674b7b51 · Published: May 2026 · Updated: Sep 09, 2026