Microsoft

How do I setup the integration with Azure Sentinel?

Preparation for the Holm Security for Microsoft Sentinel

  1. You will need to configure an API token. Follow this article to see how to set up an API token.
  2. You must have the Workspace ID and Workspace Primary Key where the Microsoft Sentinel will be installed. They can be found in your Azure portal:
    1. Search for Log Analytics workspaces.
    2. Select your Workspace and then click Agents
    3. Click on Log Analytics agent instructions to expand the information.

Set up the Holm Security for Microsoft Sentinel in Azure

To connect your Azure portal to the Security Center, follow the steps below:

  1. Log in to your Azure portal.
  2. Head to Azure Marketplace and search for Holm Security for Microsoft Sentinel.
  3. Select the Holm Security for Microsoft Sentinel and click Create.
  4. Fill in the following in the Basic menu:
    1. Select your Resource group.
    2. Select the Workspace.
  5. Click Review + Create, wait for Azure to review and for the validation to pass, and click Create.
  6. After the deployment, head to the search bar and search for Microsoft Sentinel > Date connectors.
  7. Click on Holm Security Asset Data (using Azure Functions). A window will pop up on the right side. Scroll down and click the Open Connector page.
  8. Scroll down and click Deploy to Azure.
    1. Select the preferred SubscriptionResource Group, and Location.

    2. Enter the Workspace ID, Workspace Key, API Token, and the API URL.
    3. Click Review + Create, wait for Azure to review and for the validation to pass, and click Create.
  9. Done!