Digital Shadows SearchLight for Microsoft Sentinel

Solution: Digital Shadows

Digital Shadows Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Digital Shadows
Support Tier Partner
Support Link https://www.digitalshadows.com/
Categories Security - Threat Intelligence
Version 3.0.0
Author Digital Shadows - support@digitalshadows.com
Last Updated 2025-12-14
Solution Folder Digital Shadows
Marketplace Azure Marketplace · Popularity: 🔵 Medium (56%)

The Digital Shadows Solution provides ingestion of the incidents and alerts from Digital Shadows Searchlight into the Microsoft Sentinel using the REST API.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Azure Monitor HTTP Data Collector API

b. Azure Functions

Contents

Data Connectors

This solution provides 1 data connector(s):

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
DigitalShadows_V2_CL Digital Shadows Searchlight Analytics, Workbooks

Content Items

This solution includes 4 content item(s):

Content Type Count
Analytic Rules 2
Workbooks 1
Playbooks 1

Analytic Rules

Name Severity Tactics Tables Used
Digital Shadows Incident Creation for exclude-app Medium - DigitalShadows_V2_CL
Digital Shadows Incident Creation for include-app Medium - DigitalShadows_V2_CL

Workbooks

Name Tables Used
DigitalShadows DigitalShadows_V2_CL

Playbooks

Name Description Tables Used
Digital Shadows Playbook to Update Incident Status This playbook will update the status of Microsoft Sentinel incidents to match the status of the aler... -

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.1.0 24-06-2026 Migrated ingestion from the retiring HTTP Data Collector API to the Logs Ingestion API. New table DigitalShadows_V2_CL with clean PascalCase columns; legacy DigitalShadows_CL data ages out per workspace retention. New required deployment parameter DcrWorkspaceResourceId (full resource ID of the Log Analytics workspace). Function Apps now authenticate via system-assigned managed identity (Monitoring Metrics Publisher on the DCR); legacy WorkspaceID/WorkspaceKey parameters removed. Both Function Apps upgraded to Python 3.11. Analytic rules updated to query DigitalShadows_V2_CL while keeping detection logic intact via KQL project-rename aliases.
3.0.0 04-06-2026 Updated EventReportUrl construction in both Analytic Rules
30-11-2023 Added new Entity Mapping to Analytic Rules

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index