Integrations

Blekline for Microsoft Sentinel

Enterprise-native SIEM connector — ARM deployment overview and entitlement gate.

View as Markdown

Minimum tier: Enterprise (bundled in platform commit — no separate Marketplace SKU for production).

Blekline for Microsoft Sentinel ships governance events, NHIM findings, and enforcement metadata into Microsoft Sentinel workspaces using native data connectors and ARM-deployable solution templates.

Entitlement gate

TierSentinel connector
Local / Mark / RedactNot available
EnterpriseIncluded in platform commit

Redact includes a basic HTTPS SIEM webhook (JSON/CEF). Enhanced CEF/ASIM retention and Ledger add-ons are separate from the Sentinel native connector.

For SAML/SCIM before full Enterprise, use Enterprise FastTrack private offer — SSO is not sold on Mark.

ARM deployment overview (stub)

Production deployment uses an Azure Resource Manager template published as blekline-for-sentinel (Azure Application offer). Operator steps:

  1. Prerequisites: Active Enterprise workspace on app.blekline.com; Sentinel workspace in the buyer subscription; outbound HTTPS from Blekline sidecar or control-plane sync to Azure Monitor.
  2. Deploy template: Partner Center preview → Deploy to Azure → parameterize workspaceId, bleklineTenantId, eventHubOrLogAnalyticsResourceId.
  3. Configure connector: Map Blekline event types (governance.tool_deny, nhim.finding, lineage.contamination) to Sentinel tables (custom log or ASIM-aligned).
  4. Validate ingest: Send test event from Operations → Integrations → Sentinel; confirm row in Sentinel within SLA window.
  5. Harden: Restrict API keys to Sentinel egress IPs; enable dual-control on enforce mode before production traffic.

Detailed runbook and parameter reference: contact enterprise@blekline.com. Public ARM artifact ships with R3 Enterprise + Azure cert.