Ellipse Gradient for Header

Microsoft Sentinel Integration Guide

Integrate Microsoft Sentinel with enterprise systems through Azure REST APIs, Log Analytics KQL queries, Entra ID OAuth 2.0, and selected Logic Apps automation callbacks.

Microsoft Sentinel integration options at a glance

Microsoft Sentinel provides Azure Resource Manager REST APIs for incidents, alerts, analytics rules, watchlists, bookmarks, data connectors, and automation rules. Its Azure Monitor Log Analytics Query API supports KQL-based access to workspace data. Sentinel automation rules and Logic Apps playbooks can provide selected event-driven callbacks to a Martini API, although coverage depends on the configured trigger and playbook. Microsoft Entra ID OAuth 2.0 and Azure RBAC govern access. Martini can orchestrate scheduled polling, API calls, callback processing, pagination, checkpointing, transformation, enrichment, and controlled writes to downstream systems.

Integration pointSupported by Microsoft Sentinel?Common use casesHow Martini supports it
Azure Resource Manager REST APIsYesManage or retrieve Sentinel incidents, alerts, analytics rules, watchlists, bookmarks, data connectors, and automation rules. Resource-specific API versions and Azure scopes must be selected.Martini can consume documented REST endpoints, generate reusable API assets from definitions where available, map responses, and orchestrate create, update, and retrieval workflows.
Azure Monitor Log Analytics Query APIYesRun KQL queries against authorized Sentinel workspaces for incident reporting, alert analysis, security trends, and incremental synchronization.Martini can submit KQL queries, process tabular results, aggregate or transform rows, and deliver findings to applications, databases, reports, or internal APIs.
Webhooks / outbound callbacksLimitedSelected Sentinel alerts or incidents can invoke automation rules and Logic Apps playbooks that call HTTP endpoints. Coverage depends on the configured trigger and playbook.Martini can expose a REST API to receive callbacks, validate and deduplicate payloads, enrich them, apply routing rules, and invoke downstream workflows.
Bulk / asynchronous query patternsLimitedAzure Monitor supports batch query patterns, while Sentinel management operations may be asynchronous or paginated. There is no universal bulk API for every Sentinel resource.Martini can batch bounded queries, process continuation links, control concurrency, checkpoint progress, and retry transient operations.
AuthenticationYesMicrosoft Entra ID OAuth 2.0 bearer tokens and Azure RBAC authorize service-to-service and delegated access to Azure management and Log Analytics APIs.Martini can store tenant and application configuration as secrets, acquire tokens through configured authentication flows, and separate read and write workflow permissions.
Data connectorsYesSentinel data connectors bring Microsoft and partner data into workspaces using source-specific Azure services, agents, APIs, diagnostic settings, or event streams.Martini can integrate with the relevant source or Azure endpoint and can query or process the resulting Sentinel data; connector behavior must be treated as source-specific.
File / attachment APIsNot confirmedSentinel is not primarily a file or attachment platform; connected Azure services, Logic Apps, storage, or third-party systems generally handle file exchange.Martini can integrate with the separate storage or file endpoint when identified, but should not assume a general Sentinel attachment API.
Database / analytics accessYesWorkspace data is accessed through the Azure Monitor Log Analytics Query API and KQL rather than direct SQL, JDBC, or database connectivity.Martini can consume query results over HTTPS, transform rows, and persist them to an approved target without requiring direct workspace database access.

How Microsoft Sentinel exposes data and business events

Microsoft Sentinel REST APIs

Microsoft Sentinel exposes Azure Resource Manager REST APIs for incidents, alerts, analytics rules, watchlists, bookmarks, data connectors, automation rules, and related resources. Operations require the correct subscription, resource group, workspace, resource path, API version, Entra permissions, and Azure RBAC scope.

Martini implementation pattern

Martini implementation pattern: Martini workflows authenticate with Entra ID, call the resource-specific Sentinel endpoint, follow pagination or asynchronous responses, validate the result, map it to a canonical model, and write to a target or expose a normalized Martini API. Separate read and write workflows can use appropriately scoped identities.

Implementation sequence

Acquire an Entra ID access token for the Azure management resource
Call the selected Sentinel REST resource with the configured subscription and workspace
Follow pagination or asynchronous operation status until the result is complete
Validate the response and preserve the Sentinel object identifier
Map the resource to the canonical or target data model
Create or update the target using an idempotent external key

Log Analytics Query API

Sentinel workspace data is queried through Azure Monitor's Log Analytics Query API using KQL. This is the primary analytics interface for retrieving security events, alert-related data, summaries, and incremental findings; it is not direct SQL or JDBC access.

Martini implementation pattern

Martini implementation pattern: A scheduled workflow submits bounded KQL queries, uses explicit projections and time windows, processes returned rows, and stores a checkpoint with an overlap window. Martini can aggregate results, apply business rules, and send reports or synchronized findings to downstream systems.

Implementation sequence

Start a scheduled workflow for the reporting or synchronization interval
Acquire an Entra ID token with authorized workspace query access
Submit a bounded KQL query with an explicit time window
Process returned tables and rows while preserving source timestamps
Apply aggregation, filtering, enrichment, and deduplication rules
Persist results and the next checkpoint for the following run

Automation callbacks and playbooks

Sentinel automation rules can invoke Logic Apps playbooks, and Logic Apps can call HTTP endpoints. This provides selected event-driven notification or response flows rather than an unrestricted webhook stream for every Sentinel object.

Martini implementation pattern

Martini implementation pattern: A Logic Apps playbook sends a selected alert or incident payload to a Martini REST API. Martini authenticates or validates the request, retrieves the current Sentinel resource when necessary, enriches it from other systems, applies routing rules, and records the processing outcome.

Implementation sequence

Define the incident or alert condition for the Sentinel automation rule
Invoke the Logic Apps playbook for the selected event scope
Send the event payload to the Martini REST API
Validate the callback and reject malformed or duplicate requests
Retrieve current Sentinel or enrichment data when the payload is incomplete
Route the normalized result and persist the processing status

Batch queries and scheduled synchronization

Azure Monitor supports batch query patterns, while Sentinel resource list operations can be paginated and some Azure operations are asynchronous. Large-scale synchronization should use bounded windows, continuation handling, checkpoints, and controlled concurrency rather than assuming one universal bulk endpoint.

Martini implementation pattern

Martini implementation pattern: Martini schedules incremental workflows that query or list resources, follows continuation links, filters by available timestamps or identifiers, and upserts downstream objects. Retry policies distinguish throttling, authentication failures, transient server errors, and validation failures.

Implementation sequence

Read the last successful checkpoint and define an overlap window
Retrieve pages or submit bounded batch queries
Filter results using deterministic identifiers and update timestamps
Process records with bounded concurrency
Upsert downstream objects and record source-to-target relationships
Commit the checkpoint only after the batch completes successfully

Common Microsoft Sentinel integration patterns

Pattern 1: Synchronize Sentinel incidents with ServiceNow

When to use this pattern

Use this pattern when security operations and service management need a shared case lifecycle. Incidents are generally the appropriate unit for case synchronization, while related alerts can be retained as child detail or investigation context.

Integration direction
Microsoft Sentinel
Martini
ServiceNow
Example Mapping
Microsoft Sentinel FieldCanonical FieldTarget Field
incidentNumbersourceCaseIdcorrelation_id
severityprioritypriority
statuscaseStatusstate
titlesummaryshort_description
Martini implementation pattern

A scheduled Martini workflow queries new or changed Sentinel incidents, follows pagination, and maps severity, status, title, description, tactics, techniques, entities, owners, and timestamps. It enriches records where required, then creates or updates ServiceNow using the Sentinel incident ID as the external key. The workflow uses an overlap window, idempotent upserts, retry-after handling, and an exception path for validation failures.

Martini capabilities used
  • workflows
  • API consumption
  • OAuth 2.0 authentication
  • data mapping
  • business rules
  • checkpointing
  • error handling

Pattern 2: Route selected Sentinel incidents to Jira

When to use this pattern

Use this pattern when application, infrastructure, or engineering teams need actionable remediation work items rather than full security-case ownership. Routing can depend on severity, analytics rule, affected entity, subscription, resource group, or watchlist match.

Integration direction
Microsoft Sentinel
Martini
Jira
Example Mapping
Microsoft Sentinel FieldCanonical FieldTarget Field
titleworkItemSummarysummary
descriptioninvestigationDetailsdescription
severityriskLevelpriority
incidentUrlinvestigationLinkcustomfield_security_link
Martini implementation pattern

Martini receives selected automation callbacks or polls qualifying incidents, evaluates routing rules, and transforms the incident into a Jira issue with a Sentinel investigation link. It stores the Sentinel ID as a deduplication key, updates existing issues when status changes, and routes rejected or failed writes to an operational error path with retry controls.

Martini capabilities used
  • workflow orchestration
  • API consumption
  • data transformation
  • conditional routing
  • idempotency
  • retry handling

Pattern 3: Produce KQL-based security reporting

When to use this pattern

Use this pattern for daily or hourly summaries such as high-severity incidents, unresolved cases by owner, alert volume by analytics rule, repeated failed sign-ins, or activity associated with selected Entra ID users or Azure resources.

Integration direction
Microsoft Sentinel
Martini
Microsoft Power BI
Example Mapping
Microsoft Sentinel FieldCanonical FieldTarget Field
TimeGeneratedeventTimeUtcevent_time
AlertCountalertCountalert_count
Severityseverityseverity
OwnerassignedOwnerowner
Martini implementation pattern

A scheduled Martini workflow submits a bounded KQL query through the Log Analytics Query API, projects only required columns, aggregates results, and maps rows into a reporting model. It can publish the result to an internal API or reporting destination, retain query checkpoints, and retry transient query failures without duplicating completed reporting periods.

Martini capabilities used
  • scheduler triggers
  • API consumption
  • JSON handling
  • data mapping
  • aggregation
  • checkpointing
  • monitoring

Pattern 4: Enrich callback-driven Sentinel incidents

When to use this pattern

Use this pattern when selected Sentinel conditions should trigger near-real-time enrichment or notification. It is suitable for defined automation-rule and playbook scopes, not as a universal change feed for every Sentinel object.

Integration direction
Microsoft Sentinel
Azure Logic Apps
Martini
PagerDuty
Example Mapping
Microsoft Sentinel FieldCanonical FieldTarget Field
incidentIdsourceIncidentIddedup_key
severityurgencyurgency
titlealertSummarysummary
entitiesaffectedAssetscustom_details.assets
Martini implementation pattern

A Sentinel automation rule invokes a Logic Apps playbook that calls a Martini API. Martini validates the callback, retrieves current incident data if needed, enriches entities from an approved source, applies severity and responder rules, and calls PagerDuty. The workflow returns a controlled response, logs correlation identifiers, and uses deduplication and retry handling for downstream notification failures.

Martini capabilities used
  • API exposure
  • webhook consumption
  • workflow orchestration
  • data enrichment
  • business rules
  • error handling

Applications commonly integrated with Microsoft Sentinel

Microsoft Sentinel commonly participates in Microsoft security, Azure operations, and enterprise response workflows. Martini can coordinate Sentinel APIs, Log Analytics queries, Logic Apps callbacks, and downstream application APIs without coupling business rules to a single point-to-point script.

Application Scenario Direction Martini Pattern
Microsoft Defender XDR Correlate endpoint, identity, email, and cloud security detections with Sentinel incidents and investigations. Microsoft Defender XDR → Martini → Microsoft Sentinel Use API-based ingestion or retrieval, normalize detection and incident identifiers, correlate related alerts, and apply rules before creating or updating Sentinel resources. Use idempotent keys and retry transient Azure failures.
Microsoft Entra ID Bring sign-in, audit, identity-risk, and directory-related security data into Sentinel workflows and enrich investigations with identity context. Microsoft Entra ID → Martini → Microsoft Sentinel Authenticate with Entra ID OAuth 2.0, retrieve permitted identity or security data, map users and directory attributes to Sentinel-related workflows, and preserve tenant and object identifiers for traceability.
Azure Logic Apps Execute Sentinel playbooks, enrich incidents, automate response actions, and deliver selected event payloads to external APIs. Microsoft Sentinel → Azure Logic Apps → Martini Configure a Sentinel automation rule and Logic Apps playbook to invoke a Martini REST API for selected conditions. Validate the callback, enrich the payload, route it by severity or entity, and return or persist an actionable response.
ServiceNow Synchronize security incidents, assignments, statuses, and remediation workflows with an enterprise service-management process. Microsoft Sentinel → Martini → ServiceNow Poll changed Sentinel incidents or receive selected playbook callbacks, map severity, status, ownership, entities, and investigation links, then create or update ServiceNow records using the Sentinel incident ID as an external key.
Splunk Exchange security data with an existing SIEM or security operations environment during coexistence, migration, or consolidated monitoring initiatives. Splunk → Martini → Microsoft Sentinel Use the relevant source and destination APIs or configured export path, normalize alert and incident identifiers, apply routing rules, and maintain checkpoints so repeated polling does not create duplicate security cases.
Jira Create engineering or infrastructure remediation work items from selected Sentinel incidents. Microsoft Sentinel → Martini → Jira Route incidents using severity, analytics rule, affected entity, subscription, resource group, or watchlist matches; create Jira issues with investigation links and upsert using the Sentinel incident ID.
PagerDuty Notify on-call responders and create response incidents for selected Sentinel severities or automation conditions. Microsoft Sentinel → Martini → PagerDuty Receive selected automation callbacks or poll qualifying incidents, transform severity and responder data into the PagerDuty request model, and apply deduplication and retry handling around notification calls.

How to build a Microsoft Sentinel integration in Martini

Objective

Establish the Azure and target-system security model before implementing business logic.

Instructions in Martini

  • Create or identify an Entra application and choose client credentials or delegated access as appropriate.
  • Store tenant IDs, client secrets or certificates, subscription IDs, resource groups, workspace identifiers, and target credentials in Martini secrets or environment configuration.
  • Assign the narrowest practical Sentinel and Azure RBAC permissions for each workflow.

Objective

Select polling, scheduled analytics, or selected automation callbacks according to the required event coverage.

Instructions in Martini

  • Use a scheduler for reconciliation, KQL reporting, or broad change detection.
  • Use Sentinel automation rules and Logic Apps when a defined alert or incident condition can invoke an HTTP callback.
  • Do not assume that Sentinel provides a universal webhook stream.

Objective

Obtain current Sentinel resources or workspace results using the appropriate API surface.

Instructions in Martini

  • Call the Azure Resource Manager Sentinel REST API for incidents, alerts, rules, watchlists, bookmarks, connectors, or automation resources.
  • Call the Log Analytics Query API for KQL-based workspace analytics.
  • Handle pagination, continuation links, bounded query windows, and asynchronous responses.

Objective

Coordinate retrieval, enrichment, validation, routing, and target writes as a maintainable Martini workflow.

Instructions in Martini

  • Separate authentication, retrieval, transformation, business rules, and target operations into reusable workflow logic where practical.
  • Retrieve current resources when callback payloads are incomplete or stale.
  • Persist checkpoints and source-to-target identifiers at controlled points in the workflow.

Objective

Convert Sentinel objects and KQL rows into a canonical model and the target application's schema.

Instructions in Martini

  • Map severity, status, ownership, titles, descriptions, timestamps, entities, tactics, techniques, and investigation links explicitly.
  • Normalize timestamps to UTC and tolerate optional fields, nested entities, and schema additions.
  • Preserve useful unknown investigation fields when audit or troubleshooting requirements justify it.

Objective

Determine which incidents, alerts, query results, or resource changes should be propagated and how they should be routed.

Instructions in Martini

  • Use severity, analytics rule, entity type, subscription, resource group, watchlist match, or ownership to route processing.
  • Decide whether the target receives one record per incident, one per alert, or a parent incident with related alerts.
  • Use stable Sentinel incident or alert identifiers for idempotency.

Common Microsoft Sentinel data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
IncidentsGrouped security cases requiring investigation, ownership, status changes, classification, and response.ServiceNow, Jira, PagerDuty, Microsoft Defender XDRMartini retrieves or receives selected incidents, uses the incident ID as an external key, maps severity and status, enriches entities, and performs idempotent create-or-update processing.
AlertsDetections or notifications that can contribute to incidents and provide detection-level detail.Microsoft Defender XDR, Splunk, Jira, data warehousesMartini can retrieve alerts through Sentinel APIs or query related data, preserve alert-to-incident relationships, filter by rule or severity, and route qualifying alerts.
Analytics rulesDetection logic that evaluates workspace data and generates alerts or incidents.Security administration APIs, configuration repositories, reporting systemsMartini can inventory or manage permitted rule resources, normalize rule metadata, and apply controlled change workflows with API-version-aware configuration.
WatchlistsReference datasets used by analytics rules and investigations, such as trusted or monitored entities.Identity systems, CMDBs, data warehouses, security operations toolsMartini can synchronize approved reference data, validate schemas, map source identifiers, and use controlled upserts while respecting Sentinel permissions.
BookmarksSaved investigation references to events or query results for analyst review.Case-management systems, investigation portals, reporting storesMartini can retrieve or create permitted bookmarks, map query and investigation context, and associate them with downstream incidents or cases.
Data connectorsConfigurations that bring Microsoft or third-party data sources into Sentinel.Azure services, Microsoft security products, partner security toolsMartini can inventory connector configuration or coordinate source-side integration workflows, while treating ingestion behavior and supported data types as connector-specific.

Authentication and security considerations

Microsoft Entra ID and Azure RBAC

Microsoft Sentinel integrations generally use Entra ID OAuth 2.0 bearer tokens. Server-to-server Martini workflows can use client credentials with a secret or certificate, while delegated access is appropriate when an integration acts for a signed-in user.

Azure Resource Manager APIs commonly use the Azure management resource audience. Log Analytics query access also requires Entra authorization. Assign the narrowest practical Sentinel role and Azure RBAC scope, such as Microsoft Sentinel Reader, Responder, or Contributor, according to the operation.

Secrets and permissions

  • Store client credentials, certificates, tenant IDs, subscription IDs, resource groups, and workspace identifiers in Martini secrets or environment configuration.
  • Separate read-only querying from workflows that create or update incidents, watchlists, or automation configuration.
  • Do not treat a workspace ID as a credential, and never log tokens or client secrets.

Operational considerations for Microsoft Sentinel integrations

Reliability and scale

  • Keep Sentinel API versions configurable because versions differ by resource and may include stable or preview behavior.
  • Follow pagination and continuation links; use bounded KQL time windows, explicit projections, and batch queries where appropriate.
  • Handle Azure throttling with Retry-After support, exponential backoff, bounded concurrency, and separate retry policies for authentication, transient server, and validation errors.
  • Use incident or alert IDs as idempotency keys and retain overlap windows around checkpoints to account for ingestion delay.

Data and schema behavior

  • Decide whether downstream systems receive incidents, alerts, or incidents with related alerts because these objects are not interchangeable.
  • Normalize Azure timestamps to UTC and tolerate missing optional fields, new entity types, and additional evidence.
  • Capture HTTP status, Azure correlation identifiers, source object IDs, query context, retry counts, and target IDs without recording unnecessary sensitive payloads.

Testing

Test API permissions, pagination, throttling, duplicate delivery, delayed ingestion, malformed callback payloads, schema changes, and target-system failures with representative Sentinel objects and KQL results.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration instead of isolated scripts

Martini provides a maintainable workflow layer around Sentinel REST APIs, Log Analytics queries, Logic Apps callbacks, and downstream applications. Teams can keep authentication, pagination, transformation, business rules, retries, checkpoints, and monitoring in reusable integration assets rather than duplicating them across scripts.

Controlled APIs and reusable models

Martini can expose a controlled API that abstracts Sentinel operations for internal consumers, normalize incidents and alerts into canonical models, and apply consistent authorization and validation before data reaches target systems.

Operational consistency

  • Support scheduled, event-driven, and API-led integration patterns in one platform.
  • Centralize mapping, enrichment, idempotency, retry, and exception handling.
  • Keep environment-specific credentials, resource scopes, and API versions configurable for safer deployment and maintenance.

Frequently asked questions

How can Microsoft Sentinel be integrated with enterprise systems?

Microsoft Sentinel can be integrated through its Azure Resource Manager REST APIs, the Azure Monitor Log Analytics Query API for KQL, Microsoft Entra ID OAuth 2.0, data-connector-specific ingestion paths, and selected automation callbacks delivered through Logic Apps playbooks. Scheduled workflows are useful for broader synchronization and reconciliation.

Can Martini integrate with Microsoft Sentinel?

Yes. Martini can consume Microsoft Sentinel REST APIs and the Log Analytics Query API, authenticate with Microsoft Entra ID OAuth 2.0, expose an API for selected Logic Apps callbacks, and orchestrate transformations, enrichment, synchronization, and error handling.

Do I need a connector to integrate Microsoft Sentinel with Martini?

No. A dedicated Microsoft Sentinel connector is not required. Martini can use Sentinel's native REST APIs, Azure Monitor query API, Entra ID authentication, and selected Logic Apps and HTTP callback mechanisms.

Is there any extra Lonti cost to integrate Microsoft Sentinel with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Microsoft Sentinel. Integrations are subject to the provisioned capacity of the Martini environment. Separate costs may apply from Microsoft Azure, Sentinel, Log Analytics, Logic Apps, infrastructure, data ingestion, API usage, or other third-party systems.

Which Microsoft Sentinel integration methods should be used?

Use Azure Resource Manager REST APIs for Sentinel resources such as incidents, alerts, rules, watchlists, bookmarks, and connectors. Use the Log Analytics Query API with KQL for workspace analytics. Use Logic Apps playbooks and HTTP callbacks for selected event-driven flows, and scheduled polling for reconciliation or broader coverage.

Does Microsoft Sentinel support events or webhooks?

Sentinel supports partial, workflow-based callback behavior through automation rules, Logic Apps playbooks, and HTTP actions. Coverage depends on the alert or incident trigger and playbook configuration; it is not a universal webhook stream for every Sentinel object.

How does synchronization with Microsoft Sentinel work?

Martini can poll paginated resources or run incremental KQL queries using a timestamp overlap window and a stored checkpoint. It can also process selected callbacks. Stable incident or alert IDs should be used for idempotent create-or-update processing, with the incident and related alerts modeled according to the target process.

How does Martini handle Microsoft Sentinel mapping, errors, and retries?

Martini maps nested Sentinel objects and KQL rows into canonical and target models, applies routing and validation rules, and preserves source identifiers for traceability. Workflows can distinguish authentication, throttling, transient server, and validation errors, use bounded retries and backoff, and record correlation IDs, retry state, and target identifiers.