Skip to main content
Connect Microsoft Sentinel so Myrmex can query your Log Analytics workspace with KQL, triage incidents, and fold Sentinel’s SIEM/SOAR signals into investigations. Myrmex operates Sentinel live over the Azure APIs after you grant admin consent — it runs searches and reads incidents in real time, on demand, with no Collector required and nothing stored on the Myrmex side.

What Myrmex Can Do

Incident triage

List and review Sentinel incidents as you work them.

KQL hunting

Run KQL queries against the Log Analytics workspace on demand.

Cross-stack context

Correlate Sentinel results with your other connected integrations.

Guided response

Get recommended next steps for incidents, with approval for any action.

Before You Start

Microsoft Sentinel connects from the cloud — no Collector is required. You’ll need:
  • An Azure subscription with a Sentinel-enabled Log Analytics workspace.
  • Your Tenant ID, Subscription ID, Resource Group, and Workspace Name.
  • An account that can grant admin consent and holds at least the Microsoft Sentinel Reader role on the workspace.

Step 1 — Create the Credential in Azure

1

Gather workspace details

In the Azure portal, open your Sentinel workspace and note the Subscription ID, Resource Group, and Workspace Name. Get the Tenant ID from the Microsoft Entra admin center.
2

Confirm access

Ensure the identity has at least the Microsoft Sentinel Reader role on the workspace. Add a responder role only when you want Myrmex to act on incidents.
3

Grant consent during Connect

Myrmex uses a pre-registered application. When you add the integration you’ll be redirected to Microsoft to review and grant the requested permissions (scope https://management.azure.com/.default).

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Microsoft Sentinel, then fill in:
When you connect, you’re redirected to Microsoft to sign in and grant admin consent. The authentication method and the set of granted permissions are captured automatically during consent — you don’t enter them by hand.

Connect

Click Connect and complete the Microsoft admin-consent prompt. Microsoft Sentinel then appears under Environment → Integrations, and you can start hunting and triaging incidents from the Workspace.
Prefer least privilege: Sentinel Reader covers hunting and triage, and you can add a responder role only when you want the agents to act on incidents.