Skip to main content

Microsoft Sentinel

The Microsoft Sentinel integration sends Quilr activity and findings into a Sentinel security workspace, so your SOC can investigate AI risk alongside other security events.

  • Capabilities: Send logs, Alerts & notifications
  • Direction: From Quilr
  • Category: Observability
Go toQuilrAI consoleSettingsIntegrationsLibraryMicrosoft Sentinel

Set it up​

Click Install on the Microsoft Sentinel card. Setup has three steps: Connection, Data access, and Review.

Connection​

FieldDescription
Integration nameA tenant-visible name for this installation.
Sentinel workspace labelA friendly label for the workspace.
Workspace regionThe event delivery region.

Data access​

Choose the capabilities (data flows) to enable for this installation:

CapabilityUse
Send logsPrimary use for this integration.
Alerts & notificationsAdditional supported use.

Review​

Check the settings and save. The configuration is encrypted and stored for your tenant, and the card moves to Installed.

Check that it works​

  • The card shows INSTALLED on the Installed tab. An error badge means it needs attention; open it to see the error.
  • Confirm that Quilr activity and findings arrive in the Sentinel workspace you named.
  • To change the settings later, click Configure on the installed card. Uninstall removes it.