
About the Microsoft Sentinel Integration
Microsoft Sentinel is Microsoft’s cloud-native SIEM and SOAR platform, providing intelligent security analytics, threat detection, automated incident response, and security orchestration across enterprise environments at cloud scale. Part of Synqly’s SIEM Unified API, the Microsoft Sentinel integration enables security teams to route normalized security event data from Synqly-connected tools into Sentinel’s analytics and detection engine through a standardized connector. Integrate with Microsoft Sentinel to centralize security telemetry from across your security stack into Microsoft’s platform, enabling AI-powered threat detection, investigation, and automated response.
Integration Use Cases
Get Alert
Retrieves an alert by ID.
Get Investigation
Retrieves an investigation by ID.
Patch Investigation
Updates an investigation by ID.
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Investigations
Queries investigations
Query Log Providers
Queries available log providers in the source SIEM
About Microsoft
Microsoft is the world's largest enterprise technology company and a dominant force in cybersecurity, with a security portfolio spanning identity, endpoint, cloud, and threat intelligence solutions trusted by organizations worldwide. From Azure Active Directory to Microsoft Sentinel and Defender, Microsoft's security ecosystem is a foundational layer in enterprise security programs across every industry. Teams looking to integrate with Microsoft or build a Microsoft security integration can use Synqly to connect Microsoft security services and signals with their broader security operations platform through a unified, normalized API layer.

