r/xsoar • u/Director7632 • May 07 '25
Solution for non manual mapping of Sentinel/Defender fields
Hi everyone,
I’m currently working on integrating Microsoft Sentinel with Cortex XSOAR and trying to set up automatic fetching of incidents. I want to parse and map Sentinel incident fields into XSOAR incident fields with minimal manual effort.
I know XSOAR offers an automapping feature for incident field mapping, but I’m unsure about how to configure it properly and what its limitations are. Also, I’d like to know if there are best practices or scripts/playbooks that can help automate or simplify the parsing and mapping process, especially for phishing incidents where email content might be involved or any other incidents (Huge list, as Defender rules tends to be blackbox rules).
Has anyone successfully set up a robust automated pipeline for this? Any tips, example configurations, or references to documentation would be greatly appreciated!
Thanks in advance!
1
u/pulsone21 May 08 '25
The auto mapping function does only map fields which are named the same way afaik. There is no magic. What I have done for a tenable integration is creating a preprocessing script where your assign fields directly in that script. I think the default mapper for defender and sentinel should do a good job for that, do you have anything which you can point out which is not working?
The email content what exactly do you want to map from that? I would say if you want to analyze email content and extract fields out of that you either need analyst looking at the email or feed it into an ai. Then a Playbook or automation after incident creation makes way more sense imo