Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | ContraForceEvents |
| Publisher | ContraForce |
| Used in Solutions | ContraForce |
| Collection Method | CCF |
| Connector Definition Files | ContraForceEvents_DataConnectorDefinition.json |
| DCR Definition Files | ContraForceEvents_DCR.json |
| CCF Configuration | ContraForceEvents_PollingConfig.json |
| CCF Capabilities | Basic, Paging |
The ContraForce Events connector ingests security service delivery events from your ContraForce workspace into Microsoft Sentinel: incident detections from every connected security platform, administrative access changes (role and member changes), machine credential activity, and destructive workspace actions. Use it to monitor the security operations ContraForce performs on this workspace from inside your own Sentinel.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
ContraForceEvents_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Create a ContraForce export credential
In the ContraForce portal, open Settings > Developers, select (or create) a service account that has a role on the workspace you want to connect, and add a credential with the Audit: Export scope. Copy the client ID and the one-time client secret.
Events follow the account they occur under: connect each customer workspace for its events, and your own organization account for organization-level events such as service account and credential activity.
2. Connect your ContraForce workspace
Enter your ContraForce portal URL (change it only if you use a regional portal, e.g. the UK platform), your ContraForce workspace ID (shown in the ContraForce portal URL and workspace settings), and the credential from step 1, then select Connect.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊