Solution: TheHive
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | domains |
| Version | 3.0.2 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2021-10-23 |
| Last Updated | 2026-03-13 |
| Solution Folder | TheHive |
| Marketplace | Azure Marketplace · Rating: ★★★★★ 5.0/5 (1 ratings) · Popularity: ⚪ Very Low (1%) |
TheHive solution provides the capability to ingest common The Hive events into Microsoft Sentinel through Webhooks. The Hive can notify external system of modification events (case creation, alert update, task assignment) in real time. When a change occurs in The Hive, an HTTPS POST request with event information is sent to a callback data connector URL. Refer to Webhooks documentation for more information.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor HTTP Data Collector API b. Azure Functions
This solution provides 1 data connector(s) (plus 1 discovered⚠️):
🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
TheHive_CL 🔶 |
TheHive Project - TheHive | - |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 4 content item(s) (3 in solution, 1 discovered 🔍):
| Content Type | Total | In Solution | Discovered |
|---|---|---|---|
| Playbooks | 3 | 3 | - |
| Parsers | 1 | 0 | 1 |
| Name | Description | Tables Used |
|---|---|---|
| The Hive - Create alert | Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... | - |
| The Hive - Create case | Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... | - |
| The Hive - Lock user | Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... | - |
| Name | Description | Tables Used |
|---|---|---|
| TheHive ⚠️ | - | TheHive_CL (read) |
⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.2 | 06-04-2026 | codeless Data Connector bases on Rest + api polling Moved to GA + small fix to avoid arm-ttk validation issue |
| 3.0.1 | 05-03-2026 | codeless Data Connector bases on Rest api polling |
| 3.0.0 | 05-09-2023 | Manual deployment instructions updated for Data Connector |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊