Forum Discussion
Pavan_Gelli
Oct 22, 2019Copper Contributor
Azure Sentinel API Documentation
Hi Team,
We have requirement to integrate azure sentinel with IBM Qradar/IBM Resilient for centralized incident management. I.e. we will send all the incidents generated in azure sentinel to IBM Qradar/IBM Resilient.
Do we have Azure Sentinel API's and documentation available ? Please confirm. Tx
- Ofer_Shezaf
Microsoft
YanivSh and Alp Babayigit just published a great blog on the topic:
Sending alerts enriched with supporting events from Azure to 3rd party SIEMs
~ Ofer
- Benoit_PasteauCopper Contributor
Ofer_Shezaf Do you have the link to this blog post ?!
- LinuVargheseCopper Contributor
Have you explored the option of using the graph API?
- ericjk4Brass ContributorHello!
You probably check out the Qradar documentation: but other then this way I dont know and if you find a way please let me know!
https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/t_dsm_guide_microsoft_azure_enable_event_hubs.html?cp=SS42VS_7.3.1
Thanks!- Gary BusheyCopper Contributor
ericjk4 I would agree. If there is an API you can call from Sentinel you can use a Logic App to send the data to that API to generate the incident.