⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | InfobloxSOCInsightsConnector |
| Publisher | Microsoft |
| Used in Solutions | Infoblox SOC Insights |
| Collection Method | CCF |
| Connector Definition Files | InfobloxSOCInsights_ConnectorDefinition.json |
| DCR Definition Files | InfobloxSOCInsights_DCR.json |
| CCF Configuration | InfobloxSOCInsights_PollingConfig.json |
| CCF Capabilities | APIKey |
The Infoblox SOC Insights data connector enables seamless integration of Infoblox BloxOne SOC Insight data with Microsoft Sentinel, allowing security teams to leverage advanced search, correlation, alerting, and threat intelligence enrichment capabilities. This connector provides comprehensive visibility into active security insights and threat detections, DNS security events with threat classifications, threat family and class categorizations, persistent and spreading threats across your network, and event blocking statistics. By aggregating Infoblox's advanced threat intelligence with Sentinel's powerful analytics, organizations can gain deeper insights into their security posture and respond more effectively to emerging threats. For detailed information about the underlying data sources and API capabilities, refer to the Infoblox SOC Insights documentation.
This connector ingests data into the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
InfobloxInsight_CL |
✗ | ✓ | ✗ |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connector Management
Manage your Infoblox SOC Insights connector instances
Manage multiple Infoblox connector instances. Each instance can connect to different Infoblox environments or regions. Connector Management Interface
This section is an interactive interface in the Microsoft Sentinel portal that allows you to manage your data collectors.
📊 View Existing Collectors: A management table displays all currently configured data collectors with the following information:
➕ Add New Collector: Click the "Add new collector" button to configure a new data collector (see configuration form below).
🔧 Manage Collectors: Use the actions menu to delete or modify existing collectors.
💡 Portal-Only Feature: This configuration interface is only available when viewing the connector in the Microsoft Sentinel portal. You cannot configure data collectors through this static documentation.
Add Infoblox SOC Insights Connector
Connect to Infoblox BloxOne Threat Defense API
When you click the "Add Connector" button in the portal, a configuration form will open. You'll need to provide:
To configure this connector, you need an Infoblox API key with SOC Insights access.
Log in to your Infoblox Cloud Services Portal
Navigate to Administration > API Keys
Click Create API Key
Provide a descriptive name (e.g., 'Microsoft Sentinel Integration')
Select appropriate permissions for SOC Insights access
Copy and securely store the generated API key
Note: The API key is displayed only once. Store it securely.
For detailed instructions, see How to Create an API Key.
💡 Portal-Only Feature: This configuration form is only available in the Microsoft Sentinel portal.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊