SIEM integration
Automate Microsoft Sentinel SIEM with plain language
Read Sentinel incidents and analytics rules, and send VernacSecure SuperBot™ events into a Log Analytics custom table.
What you can do
Microsoft Sentinel — Azure Management / Log Analytics API
- List incidents and their severity
- Read analytics rules and watchlists
- Send events to a Log Analytics workspace
Connection: bearer authentication against https://management.azure.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Microsoft Sentinel”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch incidents — Lists Sentinel incidents.
- Fetch analytics rules — Lists analytics rules.
- Fetch watchlists — Lists watchlists.
Write actions
This integration is read-only today. Write actions are added upstream as the vendor API exposes them.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Fortinet FortiSIEM