Installing the Microsoft Sentinel Extension

To install the Microsoft Sentinel extension, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the menu icon to open the Global menu.

    The Global menu is displayed with menu items represented as cards.

  2. In the Extensions card, click Manage.

    The Extensions page is displayed, along with the installed and available extensions under their respective tabs.

    Figure 1: Available Extensions Tab

  3. Under the Available Extensions tab, in the Microsoft Sentinel card, click Install.

    The Microsoft Sentinel installation side panel is displayed.

    Figure 2: Microsoft Sentinel Installation Side Panel

  4. Enter the required details as follows:

    • Name—Enter a name for the Microsoft Sentinel extension instance.

    • Tenant ID—Enter the tenant ID for the Microsoft Sentinel extension instance.

    • Client ID—Enter the client ID for the Microsoft Sentinel extension instance.

    • Client Secret—Enter the client secret for the Microsoft Sentinel extension instance.

    • Data Collection—Enter the Endpoint URL and Rule ID for the Microsoft Sentinel extension instance.

    • Table Mapping—Select Clients as the Data Source. This is a mandatory field. A data source indicates the location in HPE Aruba Networking Central from where data is to be exported to Microsoft Sentinel.

      • Enter a table name in the Map To Table field. This is a mandatory field. An index name must consist of only numbers, letters, underscores, and hyphens. An index name cannot contain the word kvstore.

        Note:

        The table name is automatically prefixed with Custom- and suffixed with _CL. For example, if the table name is june10_table, it becomes Custom-june10_table_CL.

      • Click the plus or delete icons to add or delete a Table Mapping configuration.

    Note:

    The previously mentioned details are obtained as follows:

    • The client ID (Application (client) ID) and <tenant-ID> (Directory (tenant) ID) are available on the Overview page of the installed Sentinel-Simple Certificate Enrollment Protocol (SCEP) application in the Microsoft Azure Active Directory portal.

    • The secret (Value) is available on the Certificates & secrets > New Client Secret page of the installed Sentinel-Simple Certificate Enrollment Protocol (SCEP) application in the Microsoft Azure Active Directory portal.

    For more information, see Microsoft Sentinel Integration Prerequisites.

  5. Click Install.

    • If installed successfully, the Installed Extensions tab displays a Microsoft Sentinel card with the defined instance name and an Active status.

      Figure 3: Active Microsoft Sentinel card

    • If there is an issue with the extension, the Installed Extensions tab, displays a Microsoft Sentinel card with the defined instance name and an Inactive status.

      Clicking the card displays the side panel with the error message at the top.