Commvault Cloud for Sentinel

Solution: Commvault Security IQ

Commvault Security IQ Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Commvault
Support Tier Partner
Support Link https://www.commvault.com/support
Categories Security - Automation (SOAR)
Version 3.0.4
Author svc.cv-securityiq@commvault.com
First Published 2023-08-17
Last Updated 2026-03-25
Solution Folder Commvault Security IQ
Marketplace Azure Marketplace · Popularity: ⚪ Very Low (2%)

This Microsoft Sentinel integration enables Commvault users to ingest alerts and other data into their Microsoft Sentinel instance. With Analytic Rules, Microsoft Sentinel can automatically create Microsoft Sentinel incidents.

Contents

Data Connectors

This solution provides 2 data connector(s):

Tables Used

This solution uses 2 table(s):

Table Used By Connectors Used By Content
CommvaultAlertsCCF_CL Commvault Security IQ (via Codeless Connector Framework) Analytics
CommvaultAlerts_CL CommvaultSecurityIQ -

Content Items

This solution includes 4 content item(s):

Content Type Count
Playbooks 3
Analytic Rules 1

Analytic Rules

Name Severity Tactics Tables Used
Commvault Cloud Alert Medium DefenseEvasion, Impact CommvaultAlertsCCF_CL

Playbooks

Name Description Tables Used
Commvault Disable Data Aging Logic App Playbook This Logic App executes when called upon by an Automation Rule. Accessing the KeyVault to retrieve v... -
Commvault Disable SAML Provider Logic App Playbook This Logic App executes when called upon by an Automation Rule. Accessing the KeyVault to retrieve v... -
Commvault Disable User Logic App Playbook This Logic App executes when called upon by an Automation Rule. Accessing the KeyVault to retrieve v... -

Additional Documentation

📄 Source: Commvault Security IQ/README.md

Commvault Security IQ - Microsoft Sentinel Integration

This integration connects Commvault Cloud with Microsoft Sentinel to enable anomaly ingestion, incident creation, investigation, and response through analytic rules, playbooks, and the Commvault Security Investigation Agent.

Table of Contents

Overview

This solution provides:

Prerequisites

Before beginning the installation, ensure you have:

Commvault Requirements

Azure Requirements

Required Azure Resources

The Commvault Security IQ (via Codeless Connector Framework) data connector collects Commvault anomaly events in Microsoft Sentinel. After you connect the connector, events are available in the CommvaultAlertsCCF_CL table.

After you select Add connector and click Connect, Microsoft Sentinel creates the connector resources and starts polling the Commvault API.

The included response playbooks have separate prerequisites: they use an Azure Key Vault to retrieve Commvault credentials and an Azure Automation Account to run the remediation runbooks. These resources are not required for CCF data ingestion.

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.6 04-08-2026 Updated the CCF connector and solution documentation.
3.0.5 27-07-2026 Added Commvault Security IQ (via Codeless Connector Framework) data connector, introduced CommvaultAlertsCCF_CL custom table and Data Collection Rule (DCR), updated analytics rule to detect client anomalies using AnomalyType, enhanced connector UI with sample queries and configuration guidance, and updated solution documentation for CCF-based deployment.
3.0.4 05-03-2025 Migrate to new data ingestion model via DCR & DCE setup
3.0.3 12-09-2025 Enhanced Data connector with configurable event collection and streamlined deployment
3.0.2 28-03-2024 Update Playbook - Bug fix in disabling data aging
3.0.1 28-03-2024 Adding Data Connector for Commvault Sentinel Integration
3.0.0 21-08-2023 Initial Solution Release

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index