Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | RubrikSecurityEventsPush |
| Publisher | Rubrik |
| Used in Solutions | RubrikSecurityCloud |
| Collection Method | CCF Push |
| Connector Definition Files | RubrikSecurityCloud_ConnectorDefinition.json |
| DCR Definition Files | RubrikSecurityCloud_DCR.json |
| CCF Configuration | RubrikSecurityCloud_DataConnector.json |
| CCF Capabilities | Push |
| Ingestion API | Log Ingestion API — CCF Push connectors use DCR-based Log Ingestion API |
| Custom Log V1 Tables | Yes 🔶 — ingests into tables with type-suffixed columns |
The Rubrik Security Cloud Security Events (Push) connector ingests security events from Rubrik Security Cloud into Microsoft Sentinel in real time using the Codeless Connector Framework (CCF) Push pattern. Rubrik Security Cloud webhooks authenticate with OAuth 2.0 and post events directly to the Azure Monitor Logs Ingestion API, with no intermediate compute to deploy or operate. Events are routed to per-category tables for anomalies, ransomware analysis, threat hunts, and all other events.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
Rubrik_Anomaly_Data_CL 🔶 |
✓ | ✓ | ✓ |
Rubrik_Events_Data_CL 🔶 |
✓ | ✓ | ✓ |
Rubrik_Ransomware_Data_CL 🔶 |
✓ | ✓ | ✓ |
Rubrik_ThreatHunt_Data_CL 🔶 |
✓ | ✓ | ✓ |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Deploy the ingestion resources
This connector lets Rubrik Security Cloud push security events directly to Microsoft Sentinel through the Azure Monitor Logs Ingestion API.
Selecting Deploy creates the Log Analytics tables and a Data Collection Rule (DCR), registers a Microsoft Entra application, links the DCR to that application, and assigns the required role. Rubrik Security Cloud then uses the resulting credentials to send events securely to the DCR. Deploy Rubrik Security Cloud push connector resources
2. Collect the connection details
After deployment completes, copy these values. You will enter them when creating the webhooks in Rubrik Security Cloud.
TenantIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
ApplicationIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
ApplicationSecretNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
DataCollectionEndpointNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
DataCollectionRuleIdNote: The value above is dynamically provided when these instructions are presented within Microsoft Sentinel.
3. Create the webhooks in Rubrik Security Cloud
Create one webhook per event category. Each webhook posts to the same Data Collection Endpoint but targets a different stream, which determines the destination table.
In Rubrik Security Cloud, create each webhook with the Microsoft Sentinel provider and set the authentication type to OAuth 2.0 using these values:
| Setting | Value |
|---|---|
| Grant type | client_credentials |
| Token URL | <Microsoft Entra ID Token Endpoint>/<Tenant ID>/oauth2/v2.0/token |
| Client ID | <Application ID> |
| Client secret | <Application Secret> |
| Scope | https://monitor.azure.com//.default |
Replace <Microsoft Entra ID Token Endpoint> with the Microsoft Entra ID authentication endpoint for your Azure cloud, and <Tenant ID>, <Application ID> and <Application Secret> with the values for the app registration created above.
Use the following URL for each webhook, replacing <Data Collection Endpoint Uri> and <Data Collection Rule Immutable ID> with the values copied above, and <Stream Name> with the stream for that event category:
<Data Collection Endpoint Uri>/dataCollectionRules/<Data Collection Rule Immutable ID>/streams/<Stream Name>?api-version=2023-01-01
| Event category | Stream name | Destination table |
|---|---|---|
| Anomaly | Custom-Rubrik_Anomaly_Data |
Rubrik_Anomaly_Data_CL |
| Ransomware analysis | Custom-Rubrik_Ransomware_Data |
Rubrik_Ransomware_Data_CL |
| Threat hunt | Custom-Rubrik_ThreatHunt_Data |
Rubrik_ThreatHunt_Data_CL |
| All other events | Custom-Rubrik_Events_Data |
Rubrik_Events_Data_CL |
Scope each webhook's event-type and severity filters to the matching category so that events are routed to the correct table.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊