GravityZone Data Connector

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index


Attribute Value
Connector ID GravityZoneDataConnector
Publisher Bitdefender
Used in Solutions GravityZone
Collection Method Unknown (Custom Log)
Connector Definition Files GravityZone_API.json
Microsoft Learn View on Learn

This connector enables integration between Bitdefender GravityZone and Microsoft Sentinel through the Event Push Service API. Once configured, it streams all GravityZone event types directly into your Microsoft Sentinel workspace, where they are stored as logs in the GzSecurityEvents_CL table.

Key event categories such as EDR, XDR, ransomware mitigation, network sandboxing, and Exchange malware events can be automatically correlated and generate incidents through the NRT GravityZone Incident Alerts analytics rule.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
GzSecurityEvents_CL

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

  1. Click the Deploy to Azure button below and fill in the required parameters.

Deploy To Azure

  1. Collect the Logs Ingestion URL from gz-sentinel-dce Data Collection Endpoint

  2. Collect the Immutable ID from gz-sentinel-dcr Data Collection Rule

  3. Go to your GravityZone Cloud account and navigate to My Account. Create an API key with Event Push Service permissions.

  4. Configure your Event Push Service settings using this article. Customers | Partners.

Please note that after the successful deployment of the Data Connector & successful setup of GravityZone's Event Push Service, the system will receive Activity Log data in near-real-time. A short delay may occur between data transmission and its appearance in the Microsoft Sentinel Logs section.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index