TheHive Solution

Solution: TheHive

TheHive Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com
Categories domains
Version 3.0.2
Author Microsoft - support@microsoft.com
First Published 2021-10-23
Last Updated 2026-03-13
Solution Folder TheHive
Marketplace Azure Marketplace · Rating: ★★★★★ 5.0/5 (1 ratings) · Popularity: ⚪ Very Low (1%)

TheHive solution provides the capability to ingest common The Hive events into Microsoft Sentinel through Webhooks. The Hive can notify external system of modification events (case creation, alert update, task assignment) in real time. When a change occurs in The Hive, an HTTPS POST request with event information is sent to a callback data connector URL. Refer to Webhooks documentation for more information.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Azure Monitor HTTP Data Collector API b. Azure Functions

Contents

Data Connectors

This solution provides 1 data connector(s) (plus 1 discovered⚠️):

🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
TheHive_CL 🔶 TheHive Project - TheHive -

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 4 content item(s) (3 in solution, 1 discovered 🔍):

Content Type Total In Solution Discovered
Playbooks 3 3 -
Parsers 1 0 1

Playbooks

Name Description Tables Used
The Hive - Create alert Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... -
The Hive - Create case Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... -
The Hive - Lock user Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... -

Parsers

Name Description Tables Used
TheHive ⚠️ - TheHive_CL (read)

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.2 06-04-2026 codeless Data Connector bases on Rest + api polling Moved to GA + small fix to avoid arm-ttk validation issue
3.0.1 05-03-2026 codeless Data Connector bases on Rest api polling
3.0.0 05-09-2023 Manual deployment instructions updated for Data Connector

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index