What Myrmex Can Do
Incident triage
List and review Sentinel incidents as you work them.
KQL hunting
Run KQL queries against the Log Analytics workspace on demand.
Cross-stack context
Correlate Sentinel results with your other connected integrations.
Guided response
Get recommended next steps for incidents, with approval for any action.
Before You Start
Microsoft Sentinel connects from the cloud — no Collector is required. You’ll need:- An Azure subscription with a Sentinel-enabled Log Analytics workspace.
- Your Tenant ID, Subscription ID, Resource Group, and Workspace Name.
- An account that can grant admin consent and holds at least the Microsoft Sentinel Reader role on the workspace.
Step 1 — Create the Credential in Azure
1
Gather workspace details
In the Azure portal, open your Sentinel workspace and note the Subscription ID, Resource Group, and Workspace Name. Get the Tenant ID from the Microsoft Entra admin center.
2
Confirm access
Ensure the identity has at least the Microsoft Sentinel Reader role on the workspace. Add a responder role only when you want Myrmex to act on incidents.
3
Grant consent during Connect
Myrmex uses a pre-registered application. When you add the integration you’ll be redirected to Microsoft to review and grant the requested permissions (scope
https://management.azure.com/.default).Step 2 — Add the Integration in Myrmex
From the Directory, choose Add Integration → Microsoft Sentinel, then fill in:When you connect, you’re redirected to Microsoft to sign in and grant admin consent. The authentication method and the set of granted permissions are captured automatically during consent — you don’t enter them by hand.
Connect
Click Connect and complete the Microsoft admin-consent prompt. Microsoft Sentinel then appears under Environment → Integrations, and you can start hunting and triaging incidents from the Workspace.Prefer least privilege: Sentinel Reader covers hunting and triage, and you can add a responder role only when you want the agents to act on incidents.