Slack Audit Solution
Microsoft Sentinel, Microsoft Corporation
Slack Audit Solution
Microsoft Sentinel, Microsoft Corporation
Slack Audit Solution
Microsoft Sentinel, Microsoft Corporation
Examine security risks, analyze your team's collaboration, diagnose configuration problems and more.
Note: Please refer to the following before installing the solution:
• Review the solution Release Notes
• There may be known issues pertaining to this Solution.
Slack Audit solution connector provides the capability to ingest Slack Audit Records events into Microsoft Sentinel through the REST API. Refer to API documentation for more information.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Log Ingestion API in Azure Monitor
b. Microsoft Sentinel Codeless Connector Platform
NOTE: Microsoft recommends installation of Slackaudit (via Codeless Connector Platform).This connector is build on the Codeless Connector Platform (CCP), which uses the Log Ingestion API, which replaces ingestion via the deprecated HTTP Data Collector API. CCP-based data connectors also support Data Collection Rules (DCRs) offering transformations and enrichment.
Important: While the updated connector(s) can coexist with their legacy versions, running them together will result in duplicated data ingestion. You can disable the legacy versions of these connectors to avoid duplication of data.
Data Connectors: 2, Parsers: 1, Workbooks: 1, Analytic Rules: 9, Hunting Queries: 10
Learn more about Microsoft Sentinel | Learn more about Solutions