Solution: Commvault Security IQ
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Commvault |
| Support Tier | Partner |
| Support Link | https://www.commvault.com/support |
| Categories | Security - Automation (SOAR) |
| Version | 3.0.4 |
| Author | svc.cv-securityiq@commvault.com |
| First Published | 2023-08-17 |
| Last Updated | 2026-03-25 |
| Solution Folder | Commvault Security IQ |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (2%) |
This Microsoft Sentinel integration enables Commvault users to ingest alerts and other data into their Microsoft Sentinel instance. With Analytic Rules, Microsoft Sentinel can automatically create Microsoft Sentinel incidents.
This solution provides 2 data connector(s):
This solution uses 2 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
CommvaultAlertsCCF_CL |
Commvault Security IQ (via Codeless Connector Framework) | Analytics |
CommvaultAlerts_CL |
CommvaultSecurityIQ | - |
This solution includes 4 content item(s):
| Content Type | Count |
|---|---|
| Playbooks | 3 |
| Analytic Rules | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Commvault Cloud Alert | Medium | DefenseEvasion, Impact | CommvaultAlertsCCF_CL |
| Name | Description | Tables Used |
|---|---|---|
| Commvault Disable Data Aging Logic App Playbook | This Logic App executes when called upon by an Automation Rule. Accessing the KeyVault to retrieve v... | - |
| Commvault Disable SAML Provider Logic App Playbook | This Logic App executes when called upon by an Automation Rule. Accessing the KeyVault to retrieve v... | - |
| Commvault Disable User Logic App Playbook | This Logic App executes when called upon by an Automation Rule. Accessing the KeyVault to retrieve v... | - |
📄 Source: Commvault Security IQ/README.md
This integration connects Commvault Cloud with Microsoft Sentinel to enable anomaly ingestion, incident creation, investigation, and response through analytic rules, playbooks, and the Commvault Security Investigation Agent.
This solution provides:
Before beginning the installation, ensure you have:
The Commvault Security IQ (via Codeless Connector Framework) data connector collects Commvault anomaly events in Microsoft Sentinel. After you connect the connector, events are available in the CommvaultAlertsCCF_CL table.
After you select Add connector and click Connect, Microsoft Sentinel creates the connector resources and starts polling the Commvault API.
The included response playbooks have separate prerequisites: they use an Azure Key Vault to retrieve Commvault credentials and an Azure Automation Account to run the remediation runbooks. These resources are not required for CCF data ingestion.
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.6 | 04-08-2026 | Updated the CCF connector and solution documentation. |
| 3.0.5 | 27-07-2026 | Added Commvault Security IQ (via Codeless Connector Framework) data connector, introduced CommvaultAlertsCCF_CL custom table and Data Collection Rule (DCR), updated analytics rule to detect client anomalies using AnomalyType, enhanced connector UI with sample queries and configuration guidance, and updated solution documentation for CCF-based deployment. |
| 3.0.4 | 05-03-2025 | Migrate to new data ingestion model via DCR & DCE setup |
| 3.0.3 | 12-09-2025 | Enhanced Data connector with configurable event collection and streamlined deployment |
| 3.0.2 | 28-03-2024 | Update Playbook - Bug fix in disabling data aging |
| 3.0.1 | 28-03-2024 | Adding Data Connector for Commvault Sentinel Integration |
| 3.0.0 | 21-08-2023 | Initial Solution Release |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊