Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/commvault.microsoft-sentinel-solution-commvaultsecurityiq-4ce5c397-4c61-4859-bcde-a0b730b3ed04/image2_Commvault.png

Commvault Cloud for Sentinel

by Commvault

Bring Commvault security signals into sentinel for faster detection and automated response

Commvault Security IQ for Microsoft Sentinel helps organizations monitor cyber resilience across their Commvault data protection environments. The solution ingests Commvault anomaly and threat events into Microsoft Sentinel, enabling centralized detection, investigation, and incident response.

Key Features

  • Ingest security-relevant Commvault anomaly and threat events into Microsoft Sentinel, including events documented in the Threat Indicators Dashboard.
  • Help reduce security blind spots and manual monitoring overhead across data protection environments.
  • Create Microsoft Sentinel incidents from Commvault anomaly events using the included analytic rule template.
  • Automate response actions such as disabling Commvault users, disabling SAML identity providers, and disabling data aging using the included playbook templates.
  • Support managed Codeless Connector Framework ingestion.

How It Works

  • Install the Commvault Security IQ solution from Microsoft Sentinel Content hub.
  • Configure the Codeless Connector Framework connector with the Commvault API endpoint and API token. The connector polls for new anomaly events and stores them in the table.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/commvault.microsoft-sentinel-solution-commvaultsecurityiq-4ce5c397-4c61-4859-bcde-a0b730b3ed04/image3_CommvaultCloudDataConnectorforMicroosftSentinel01.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies