Review the Microsoft Azure Sentinel integration settings
Review the Microsoft Azure Sentinel integration settings so that you can modify the system properties to suit your environment.
Before you begin
Important:
Microsoft has extended the deprecation of the Azure Sentinel experience in the Azure portal from March 2026 to March 2027.
If you are currently using the Azure Sentinel integration with Security Incident Response (SIR), we strongly recommend migrating to the new Defender portal integration as soon as possible. The Defender integration includes a built-in migration utility that automatically converts your existing Sentinel profiles into Defender profiles, while ensuring continuity of incidents created through Sentinel after the transition. For more information, see Microsoft Sentinel to Defender Migration Guide.
Role required: sn_si.ingestion_profile_admin
Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.
Procedure
Navigate to All > Microsoft Azure Sentinel Integration > Azure Sentinel Integration Settings.
Modify the following settings as required.
| Property Name | Description |
|---|---|
| Enforce a limit on the number of days for which sample data can be fetched.sn\_sec\_sentinel.max\_num\_of\_days\_for\_sample\_data | Maximum number of days for which you can fetch sample data from the Microsoft Azure Sentinel environment.Type: integer Default value: 7 |
| Receive updates related to new alerts that are linked to SIR.sn\_sec\_sentinel.incident\_updates | Activate the option to receive incident updates. Type: Boolean Default value: True |
| The delimiter character to split the values in Microsoft Azure Sentinel field mappings.sn\_sec\_sentinel.delimiter | The delimiter character to split the values in Microsoft Azure Sentinel field mappings.Type: String Default value: ', ' \(comma with space\) |
| Enforce a limit on the number of sample incidents that can be fetched.sn\_sec\_sentinel.max\_num\_of\_sample\_incident\_per\_call | Maximum number of sample incidents that you fetch from the Microsoft Azure Sentinel environment for ingestion. Type: integerDefault value: 5 Sample maximum value: 20 |
| Enforce a limit on the number of sentinel incidents that can be aggregated to a single incident.sn\_sec\_sentinel.max\_aggregations\_per\_si | Incident aggregation limit for a security incident. For example, if there are 102 incidents, the first 100 are aggregated to security incident\_1 and the remaining 2 to security incident\_2. Type: integerDefault value: 100 |
| Enforce a limit on the number of security incidents that can be created in a 24-hour period.sn\_sec\_sentinel.max\_si\_per\_day | Maximum number of security incidents that can be created in a 24-hour period in the ServiceNow AI Platform. Type: integerDefault value: 1000 |
| Maximum pagination limit for fetching the incident data in one REST call.sn\_sec\_sentinel.max\_page\_size | Pagination limit for fetching the incident data in one REST call from the Microsoft Azure Sentinel environment. Type: integerDefault value: 100 |
| API version value for Incidents.sn\_sec\_sentinel.sentinel\_security\_incident\_api\_version | The Microsoft API version for retrieving Sentinel incidents.Default value: 2021-10-01 |
| API version value for Alerts.sn\_sec\_sentinel.sentinel\_security\_alert\_api\_version | The Microsoft API version for retrieving Sentinel alerts.Default value: 2021-10-01 |
| API version value for Entities.sn\_sec\_sentinel.sentinel\_security\_entities\_api\_version | The Microsoft API version for retrieving Sentinel entities.Default value: 2021-10-01 |
| sn\_sec\_sentinel.logging.verbosity | The log verbosity level of the application, meaning the name of the type of information. You can also update the value to the following options:- error - warn - info - debug Default value: info. |
Click Save.
Your modified integration settings are applied in the next polling interval as defined in the profile.