Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Review the Microsoft Azure Sentinel integration settings

Review the Microsoft Azure Sentinel integration settings so that you can modify the system properties to suit your environment.

Before you begin

Important:

Microsoft has extended the deprecation of the Azure Sentinel experience in the Azure portal from March 2026 to March 2027.

If you are currently using the Azure Sentinel integration with Security Incident Response (SIR), we strongly recommend migrating to the new Defender portal integration as soon as possible. The Defender integration includes a built-in migration utility that automatically converts your existing Sentinel profiles into Defender profiles, while ensuring continuity of incidents created through Sentinel after the transition. For more information, see Microsoft Sentinel to Defender Migration Guide.

Role required: sn_si.ingestion_profile_admin

Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

Procedure

  1. Navigate to All > Microsoft Azure Sentinel Integration > Azure Sentinel Integration Settings.

  2. Modify the following settings as required.

Property NameDescription
Enforce a limit on the number of days for which sample data can be fetched.sn\_sec\_sentinel.max\_num\_of\_days\_for\_sample\_dataMaximum number of days for which you can fetch sample data from the Microsoft Azure Sentinel environment.Type: integer Default value: 7
Receive updates related to new alerts that are linked to SIR.sn\_sec\_sentinel.incident\_updatesActivate the option to receive incident updates. Type: Boolean Default value: True
The delimiter character to split the values in Microsoft Azure Sentinel field mappings.sn\_sec\_sentinel.delimiterThe delimiter character to split the values in Microsoft Azure Sentinel field mappings.Type: String Default value: ', ' \(comma with space\)
Enforce a limit on the number of sample incidents that can be fetched.sn\_sec\_sentinel.max\_num\_of\_sample\_incident\_per\_callMaximum number of sample incidents that you fetch from the Microsoft Azure Sentinel environment for ingestion. Type: integerDefault value: 5 Sample maximum value: 20
Enforce a limit on the number of sentinel incidents that can be aggregated to a single incident.sn\_sec\_sentinel.max\_aggregations\_per\_siIncident aggregation limit for a security incident. For example, if there are 102 incidents, the first 100 are aggregated to security incident\_1 and the remaining 2 to security incident\_2. Type: integerDefault value: 100
Enforce a limit on the number of security incidents that can be created in a 24-hour period.sn\_sec\_sentinel.max\_si\_per\_dayMaximum number of security incidents that can be created in a 24-hour period in the ServiceNow AI Platform. Type: integerDefault value: 1000
Maximum pagination limit for fetching the incident data in one REST call.sn\_sec\_sentinel.max\_page\_sizePagination limit for fetching the incident data in one REST call from the Microsoft Azure Sentinel environment. Type: integerDefault value: 100
API version value for Incidents.sn\_sec\_sentinel.sentinel\_security\_incident\_api\_versionThe Microsoft API version for retrieving Sentinel incidents.Default value: 2021-10-01
API version value for Alerts.sn\_sec\_sentinel.sentinel\_security\_alert\_api\_versionThe Microsoft API version for retrieving Sentinel alerts.Default value: 2021-10-01
API version value for Entities.sn\_sec\_sentinel.sentinel\_security\_entities\_api\_versionThe Microsoft API version for retrieving Sentinel entities.Default value: 2021-10-01
sn\_sec\_sentinel.logging.verbosityThe log verbosity level of the application, meaning the name of the type of information. You can also update the value to the following options:- error - warn - info - debug Default value: info.
  1. Click Save.

    Your modified integration settings are applied in the next polling interval as defined in the profile.