Oct 22 2019
07:46 AM
- last edited on
Dec 23 2021
10:17 AM
by
TechCommunityAP
Oct 22 2019
07:46 AM
- last edited on
Dec 23 2021
10:17 AM
by
TechCommunityAP
Hi Team,
We have requirement to integrate azure sentinel with IBM Qradar/IBM Resilient for centralized incident management. I.e. we will send all the incidents generated in azure sentinel to IBM Qradar/IBM Resilient.
Do we have Azure Sentinel API's and documentation available ? Please confirm. Tx
Oct 22 2019 08:48 AM
Oct 22 2019 01:02 PM
@ericjk4 I would agree. If there is an API you can call from Sentinel you can use a Logic App to send the data to that API to generate the incident.
Jun 09 2020 10:32 PM
Have you explored the option of using the graph API?
Jun 14 2020 11:51 PM
@YanivSh and @Alp Babayigit just published a great blog on the topic:
Sending alerts enriched with supporting events from Azure to 3rd party SIEMs
~ Ofer
Apr 16 2021 06:40 AM
@Ofer_Shezaf Do you have the link to this blog post ?!