Azure/Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 45 minutes ago
Added to GitGenius on September 11th, 2026
Created on August 18th, 2018
Open Issues & Pull Requests: 121 (+0)
GitHub issues: Enabled
Number of forks: 3,807
Total Stargazers: 6,115 (+0)
Total Subscribers: 241 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 8.3 hours
Mean response time: 14.9 hours
90th percentile: 2.3 days
Tracked items: 673

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 100% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Almost all tracked open issues have seen activity in the last three months. Only 5% of issues opened in the past year have been closed.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 40
New in 7 days: 6
Closed in 7 days: 2
Avg open age: 49 days
Stale 30+ days: 13
Stale 90+ days: 0

Recent activity

Opened in 7 days: 6
Closed in 7 days: 2
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • Connector (273)
  • Analytic Rules (84)
  • Codeless Connector Framework (CCF) Connector (84)
  • Solution (56)
  • feature request (52)
  • Parser (44)
  • Playbook (44)
  • ASIM (33)

Detailed Description

Azure Sentinel is a cloud-native SIEM platform that delivers intelligent security analytics across an entire enterprise infrastructure.

The platform addresses the challenge of detecting, investigating, and responding to security threats at scale by centralizing log and event data from across an organization's environment. It applies machine learning and behavioral analytics to identify suspicious patterns and potential threats that might otherwise go unnoticed. The approach integrates data collection, threat detection, and incident response into a unified system accessible through a cloud-based interface, eliminating the need to maintain on-premises security infrastructure.

Organizations should consider Azure Sentinel if they operate primarily on Azure or have hybrid cloud environments where centralized security monitoring is a priority. It suits enterprises that need to correlate security events across multiple data sources and want built-in machine learning capabilities for threat detection without extensive manual tuning. Teams already invested in the Azure ecosystem will find natural integration with existing services and tooling. The platform is particularly valuable for organizations lacking dedicated security operations center expertise, as its automated analytics reduce the manual work required to identify genuine threats.

The project maintains active development with regular updates to detection rules and analytics capabilities. The codebase includes sample code and templates that demonstrate integration patterns and extend the platform's functionality. Community contributions flow steadily into the repository, reflecting ongoing refinement of detection logic and response playbooks. The project demonstrates responsiveness to emerging threat landscapes through continuous updates to its security analytics and detection mechanisms.