Airlock Digital for Microsoft Sentinel

Solution: AirlockDigital

AirlockDigital Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Airlock Digital
Support Tier Partner
Support Link https://www.airlockdigital.com/
Categories Security - Threat Protection
Version 3.2.0
Author Airlock Digital - support@airlockdigital.com
First Published 2026-08-04
Last Updated 2026-08-26
Solution Folder AirlockDigital
Marketplace Azure Marketplace · Popularity: 🔵 Medium (69%)

The Airlock Digital solution for Microsoft Sentinel ingests application control and execution logs from Airlock Digital using the Codeless Connector Platform (CCP), giving visibility into file executions, server activity, and policy changes.

The solution provides three data connectors so you can choose the one that matches your deployment:

a. Airlock Digital (Push) -- for self-hosted servers and Airlock Digital SaaS running v7.0 or higher. Airlock's external logging feature streams execution history, server activity, and policy change events into Microsoft Sentinel in near real time, authenticating with a Microsoft Entra application. This is the recommended connector.

b. Airlock Digital (Poll) -- for self-hosted servers older than v7.0 that do not support push-based logging. Periodically pulls execution history and server activity from the Airlock REST API using a user API key.

c. Airlock Digital (Poll - SaaS) -- for the Airlock Digital hosted SaaS offering, authenticating with a user API key together with your directory and tenant identifiers.

The solution also installs ASIM parsers that normalize Airlock data into the Process Event and Audit Event schemas, plus a workbook summarizing application control activity.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Codeless Connector Platform (CCP)

Contents

Data Connectors

This solution provides 3 data connector(s) (plus 1 discovered⚠️):

🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.

Tables Used

This solution uses 5 table(s):

Table Used By Connectors Used By Content
AirlockDigitalExecutionHistories_CL Airlock Digital (Poll - SaaS), Airlock Digital (Poll), Airlock Digital (Push), Airlock Digital connector (via Codeless Connector Framework) -
AirlockDigitalFileActivitySummary_CL Airlock Digital connector (via Codeless Connector Framework) -
AirlockDigitalPolicyChanges_CL Airlock Digital (Push) -
AirlockDigitalServerActivities_CL Airlock Digital (Poll - SaaS), Airlock Digital (Poll), Airlock Digital (Push), Airlock Digital connector (via Codeless Connector Framework) -
Operation - Workbooks

Content Items

This solution includes 4 content item(s):

Content Type Count
Parsers 3
Workbooks 1

Workbooks

Name Tables Used
AirlockDigital Operation

Parsers

Name Description Tables Used
ASimAuditEventAirlockDigital - AirlockDigitalServerActivities_CL (read)
ASimAuditEventAirlockDigitalPolicyChange - AirlockDigitalPolicyChanges_CL (read)
ASimProcessEventAirlockDigital - AirlockDigitalExecutionHistories_CL (read)

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.2.0 05-08-2026 Solution now published by Airlock Digital.
Updated Data Connector Airlock Digital (Poll).
Added new Data Connectors Airlock Digital (Push) and Airlock Digital (Poll - SaaS).
Added new Parsers and Workbook.
3.1.1 28-07-2026 Promoted the Airlock Digital data connector from public preview to general availability (GA).
3.1.0 23-07-2026 Added multi-instance support: multiple simultaneous Airlock Digital server connections via a grid and context-pane UX with a multi-select data type dropdown and per-connection friendly name. Added a ConnectorName column to all data tables to identify the originating connection. Fixed log ingestion: increased data connector poller timeout to 120s and corrected the pagination token path to slice notation for Server Activities and Execution Histories to resolve fetch timeouts and out-of-range paging errors. Removed deprecated graphQueriesTableName property (hardcoded table names in queries).
3.0.1 02-06-2026 Fixed: Removed empty ApiKeyIdentifier field for Partner Center certification compliance. Fixed UX description typo.
3.0.0 20-05-2026 Created a Data Connector for Airlock Digital CCF Container with Server Activities, Execution Histories, and File Activity Summary data streams.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index