chat
expand_more

Microsoft Sentinel Push Integration

Streamline your Sentinel deployment with our new push-based integration for faster setup, broader coverage, and greater reliability.
July 11, 2025
Third-Party Integration
API

Enhance reliability and simplify deployment with direct push-based delivery.

Abnormal now offers a push-based integration for Microsoft Sentinel, allowing you to stream security event data directly into your Log Analytics Workspace without relying on polling or custom Function Apps.

This update eliminates missed events, reduces configuration complexity from multiple components to just a Log Analytics Workspace, and expands data coverage to include Vendor Cases, Posture Changes, and Audit Logs. It is available alongside our existing pull-based model, giving you more flexibility in how you connect to Sentinel.

Now available.

Get the Latest Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.