Skip to main content
With the Microsoft Sentinel integration, you can automatically send Plerion alerts into Microsoft Sentinel as incidents, allowing your security team to investigate and respond within their existing SIEM workflows.
Note: This is a one-way outbound integration. Alerts created or updated in Plerion will appear in Microsoft Sentinel, but changes made in Sentinel will not sync back to Plerion.

Steps to integrate Microsoft Sentinel with Plerion

1

On the Plerion dashboard, go to Settings > Integrations

2

Find Microsoft Sentinel and click the + button

3

On the Connect Sentinel page, enter a name for your integration

4

Enter your Microsoft Azure credentials

Provide the following details from your Azure environment:
  • Application ID
  • Directory ID
  • Client Secret
  • Subscription ID
Then select Next.

5

Choose your Sentinel workspace settings

Select the workspace, resource group for Plerion alerts created in Sentinel.
6

Test your Microsoft Sentinel integration

Click Send test message to confirm the configuration. A test incident will be created in your chosen Sentinel workspace.

7

Finalize the setup

Click Add to complete the integration.