Microsoft Sentinel SIEM and platform solution overview

Microsoft Sentinel ISV solutions are partner-built integrations and content that extend Microsoft Sentinel for customer scenarios. As an independent software vendor (ISV), you package your product's connectors, detections, automation, and analytics experiences into a solution that customers discover, install, and use directly inside Microsoft Sentinel. A well-built solution lets customers onboard your product in minutes instead of building integrations themselves, and it gives your product a presence in the marketplaces that security teams already use.

You can build two solution types, and they target different parts of the Microsoft Sentinel experience:

  • SIEM solutions deliver detection, investigation, and automated response content for Security Operations Center (SOC) teams. They bring your product's logs into Microsoft Sentinel and turn that data into ready-to-use analytics rules, hunting queries, workbooks, playbooks, and parsers.

  • Platform solutions deliver large-scale data analysis and AI-driven experiences built on the Microsoft Sentinel data lake and graph. They include Security Copilot agents, Model Context Protocol (MCP) tools, custom graphs, and notebook jobs for scenarios that analyze large volumes of security data.

The two paths use different content types, build tooling, quality requirements, and publishing flows. Understanding the differences early helps you choose the right content path, scope your work accurately, and avoid rework before you start development and publishing. The rest of this article compares the two solution types and links to the detailed build and publish guidance for each.

Compare SIEM and platform solutions

The two solution types serve different customer needs, use different content, and publish through different stores.

SIEM solutions Platform solutions
Purpose Detection, investigation, and automated response for Security Operations Center (SOC) teams Large-scale data analysis and AI-driven scenarios that use the Microsoft Sentinel data lake and graph
Primary audience SOC analysts, threat hunters, and detection engineers Security data scientists, threat researchers, and teams building AI-assisted investigations
Typical content Data connectors, analytics rules, hunting queries, summary rules, workbooks, playbooks, and Advanced Security Information Model (ASIM) parsers Security Copilot agents, Model Context Protocol (MCP) tools, custom graphs, and notebook jobs
Foundation Microsoft Sentinel workspace and content hub Microsoft Sentinel data lake and graph
Data scope Real-time and near-real-time analytics on workspace tables Large historical and high-volume datasets stored in the data lake
Build tooling AI connector builder agent, Codeless Connector Framework (CCF), YAML content templates, and the V3 solution packaging tool KQL jobs, VS Code notebook and graph development tools, and the platform packaging flow

If you're not sure which content your scenario needs, start with Decide which components to include in your solution for SIEM solutions .

Build and publish SIEM solutions

SIEM solutions focus on detections, investigations, and automation for SOC teams. Use the following articles to plan, build content, publish, and maintain a SIEM solution.

Plan and understand the lifecycle

Build data connectors

Build detection, hunting, and visualization content

Publish and maintain

Troubleshoot solutions

If you run into data ingestion, analytics, packaging, or agent integration issues while building or publishing either solution type, see Troubleshoot solutions in Microsoft Sentinel.

Contact App Assure

If you're an independent software vendor (ISV) and need support when building a Microsoft Sentinel integration by using the Microsoft Sentinel Codeless Connector Framework, the Microsoft App Assure team might be able to assist. To engage the App Assure team, send an email to AzureSentinelPartner@microsoft.com for assistance.