Integration brief · Microsoft Sentinel ← Back to the page   Print or save as PDF
Integration brief Microsoft SentinelSecurity and Observability

Portal Activity in Sentinel, Next to Everything Else

Microsoft Sentinel is where your security team already correlates sign-ins, endpoints and cloud activity. Nexus and AI Live Insight send it three things: platform telemetry over OpenTelemetry, the audit and chain-of-custody record by export, and events by webhook the moment they happen. Sentinel's analytics rules, workbooks and retention then apply to portal activity. Nothing flows back, and the content itself never leaves.

What you can do together

  • See who touched an evidence item, from which IP address and when, in the same Sentinel workbook as the Microsoft Entra ID sign-in that preceded it, from the chain-of-custody export of Nexus.
  • Open a Sentinel incident on a media action or metadata change the moment it happens, on a webhook, rather than finding it in a report.
  • Put a High-severity AI Live Insight detection into the SOC's queue, with the camera, the confidence and the time.
  • Show an auditor that machine reads are on the record: an AI Intelligence Hub agent reading content appears in the trail you ingest, beside the human reads.

How it connects

Platform telemetry leaves over OTLP, the OpenTelemetry Protocol. An administrator sets one endpoint, the one that feeds your Sentinel workspace, and chooses OTLP over HTTP with protobuf or over gRPC. Traces, metrics and logs all use it, authenticated by API key, bearer token or basic credentials. A sampling ratio trims trace volume, and a service name and environment tag each portal so several stay distinguishable in one workspace. Sentinel is an exercised destination.

The audit record is a separate stream, and the one a compliance reviewer wants. Administrative actions go to a searchable audit log that exports for review outside the platform. The chain of custody records every action on an item with the user, email address, IP address, local date and time and the event, and exports as CSV or PDF, filtered by date, event, user, email or IP. Reads by an AI agent land in the same trail, attributed to the user who initiated them.

Webhooks carry events as they happen. The platform calls an endpoint you register on media actions, metadata changes, live session events and workflow completion, authenticated per webhook and subscribed per event or category. On AI Live Insight, each detection is sent as structured event data too. Every delivery is logged with its outcome and retries.

VIDIZMO and Microsoft Sentinel · Integration briefPage 1 of 2
How it works Microsoft SentinelSecurity and Observability
Nexus audit log of every action, sign-ins, exports, purges Platform events webhooks on media, metadata, live sessions, workflow runs webhooks, OTLP, audit export Microsoft Sentinel dashboards, correlation rules, retention, alerting on your terms incidents and reports Security operations one console for the estate, VIDIZMO events beside the rest Microsoft Sentinel VIDIZMO

A scenario

  1. 02:14A burst of webhook events arrives from the evidence portal: media actions on forty items in eleven minutes, at an hour the portal is normally quiet.
  2. 02:16A Sentinel analytics rule joins the burst to an Entra ID sign-in three minutes earlier from a device the tenant has not seen before, and opens an incident.
  3. 07:40The records supervisor, in the portal's Audit Log Reader group, exports the chain-of-custody trail for the overnight window as a PDF. It lists every item, the event, the account, the IP address and the local time, and one account made every entry.
  4. 09:00The account belongs to a contractor whose engagement ended the week before; it is disabled in Entra ID. The custody report shows which items were viewed and that none were downloaded, and goes into the incident file.
  5. Same weekThe team adds a rule on AI Live Insight webhook events from the courthouse lobby cameras, so a High-severity weapon detection reaches the SOC queue too.

What stays where

Microsoft Sentinel remains the SIEM

Analytics rules, workbooks, incidents and retention are Sentinel's. The platform sends and never reads; nothing flows back into the portal.

What leaves the platform

Traces, metrics and logs over OTLP; the audit log and the custody trail by export; events by webhook. None of these paths carries the content itself. Agent prompt tracing is a separate path to Opik or Langfuse, off by default.

Processing where you deploy

The export runs from VIDIZMO's cloud, your own cloud or on premises. An air-gapped deployment exports to a collector inside its own boundary.

Access to the trail is itself controlled

Reading the audit log is a separate entitlement from administering the portal, and log access levels decide how much of the trail each role sees.

Products and solutions

Next step

See it on your own Microsoft Sentinel instance.

We will show the connection made, the data moving and the output, then size it for your deployment.

Contact VIDIZMO

sales@vidizmo.ai

+1 571-969-2180

vidizmo.ai

Product names and logos are the property of their respective owners.Page 2 of 2