Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | InfobloxSOCInsightsDataConnector_API |
| Publisher | Infoblox |
| Used in Solutions | Infoblox, Infoblox SOC Insights |
| Collection Method | REST Pull API |
| Connector Definition Files | InfobloxSOCInsightsDataConnector_API.json |
| Ingestion API | HTTP Data Collector API — Connector definition requires workspace key (SharedKey pattern) |
The Infoblox IQ for Threat Defense Insight Data Connector allows you to easily connect your Infoblox IQ for Threat Defense Insight data with Microsoft Sentinel. By connecting your logs to Microsoft Sentinel, you can take advantage of search & correlation, alerting, and threat intelligence enrichment for each log.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
InfobloxInsight_CL |
✗ | ✓ | ✗ |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Parsers
This data connector depends on a parser based on a Kusto Function to work as expected called InfobloxInsight which is deployed with the Microsoft Sentinel Solution.
2. Infoblox IQ for Threat Defense
This data connector assumes you have access to Infoblox IQ for Threat Defense. You can find more information about it here.
3. Follow the steps below to configure this data connector 1. Generate an Infoblox API Key and copy it somewhere safe
In the Infoblox Cloud Services Portal, generate an API Key and copy it somewhere safe to use in the next step. You can find instructions on how to create API keys here.
2. Configure the Infoblox-IQ-for-TD-Get-Insights-API playbook
Create and configure the Infoblox-IQ-for-TD-Get-Insights-API playbook which is deployed with this solution. Enter your Infoblox API key and the Log Analytics Workspace Name in the appropriate parameters when prompted.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊