Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Microsoft Sentinel ISV solutions are partner-built integrations and content that extend Microsoft Sentinel for customer scenarios. As an independent software vendor (ISV), you package your product's connectors, detections, automation, and analytics experiences into a solution that customers discover, install, and use directly inside Microsoft Sentinel. A well-built solution lets customers onboard your product in minutes instead of building integrations themselves, and it gives your product a presence in the marketplaces that security teams already use.
You can build two solution types, and they target different parts of the Microsoft Sentinel experience:
SIEM solutions deliver detection, investigation, and automated response content for Security Operations Center (SOC) teams. They bring your product's logs into Microsoft Sentinel and turn that data into ready-to-use analytics rules, hunting queries, workbooks, playbooks, and parsers.
Platform solutions deliver large-scale data analysis and AI-driven experiences built on the Microsoft Sentinel data lake and graph. They include Security Copilot agents, Model Context Protocol (MCP) tools, custom graphs, and notebook jobs for scenarios that analyze large volumes of security data.
The two paths use different content types, build tooling, quality requirements, and publishing flows. Understanding the differences early helps you choose the right content path, scope your work accurately, and avoid rework before you start development and publishing. The rest of this article compares the two solution types and links to the detailed build and publish guidance for each.
Compare SIEM and platform solutions
The two solution types serve different customer needs, use different content, and publish through different stores.
| SIEM solutions | Platform solutions | |
|---|---|---|
| Purpose | Detection, investigation, and automated response for Security Operations Center (SOC) teams | Large-scale data analysis and AI-driven scenarios that use the Microsoft Sentinel data lake and graph |
| Primary audience | SOC analysts, threat hunters, and detection engineers | Security data scientists, threat researchers, and teams building AI-assisted investigations |
| Typical content | Data connectors, analytics rules, hunting queries, summary rules, workbooks, playbooks, and Advanced Security Information Model (ASIM) parsers | Security Copilot agents, Model Context Protocol (MCP) tools, custom graphs, and notebook jobs |
| Foundation | Microsoft Sentinel workspace and content hub | Microsoft Sentinel data lake and graph |
| Data scope | Real-time and near-real-time analytics on workspace tables | Large historical and high-volume datasets stored in the data lake |
| Build tooling | AI connector builder agent, Codeless Connector Framework (CCF), YAML content templates, and the V3 solution packaging tool | KQL jobs, VS Code notebook and graph development tools, and the platform packaging flow |
If you're not sure which content your scenario needs, start with Decide which components to include in your solution for SIEM solutions .
Build and publish SIEM solutions
SIEM solutions focus on detections, investigations, and automation for SOC teams. Use the following articles to plan, build content, publish, and maintain a SIEM solution.
Plan and understand the lifecycle
- Build and publish Microsoft Sentinel SIEM solutions
- Develop a SIEM solution for Microsoft Sentinel
- Decide which components to include in your solution
- Microsoft Sentinel SIEM solution quality guidelines
Build data connectors
- Build custom connectors with AI in Microsoft Sentinel
- Create a pull codeless connector (CCF)
- Create push codeless connectors (CCF)
Build detection, hunting, and visualization content
- Create analytics rules
- Create hunting queries
- Create summary rules
- Create workbooks
- Create parsers
- Create playbooks
- Develop Advanced Security Information Model (ASIM) parsers
Publish and maintain
- Publish SIEM solutions to Microsoft Sentinel
- Microsoft Sentinel solution lifecycle in Partner Center
Troubleshoot solutions
If you run into data ingestion, analytics, packaging, or agent integration issues while building or publishing either solution type, see Troubleshoot solutions in Microsoft Sentinel.
Contact App Assure
If you're an independent software vendor (ISV) and need support when building a Microsoft Sentinel integration by using the Microsoft Sentinel Codeless Connector Framework, the Microsoft App Assure team might be able to assist. To engage the App Assure team, send an email to AzureSentinelPartner@microsoft.com for assistance.