All automations

Microsoft Sentinel + n8n

Microsoft Sentinel Incident Triage

An end-to-end incident triage system designed for Microsoft Sentinel. It combines webhook ingestion, normalized incident records, entity tables, decision tracking, false-positive learning, daily metrics, and an Azure Logic App integration path.

8Data tables
3Live workflows
100Test risk score

SYSTEM ARCHITECTURE

From raw signal to accountable decision.

01 / Receive

An Azure Logic App sends the Sentinel incident to n8n.

02 / Context

Incident and entity fields are normalized into dedicated tables.

03 / Decide

Risk logic builds an explainable L1 recommendation.

04 / Improve

Decisions and daily metrics make triage quality measurable.

PROCESS

01Webhook02Normalize03Entities04Risk05Decision06Metrics

CAPABILITIES

What the automation delivers.

Sentinel incident webhook

Eight structured data tables

Entity correlation

Decision API

False-positive tracker

Logic App connection guide

SAMPLE OUTPUT

Multi-stage identity compromise

SEVERITYCritical

RISK SCORE100 / 100

RECOMMENDATIONImmediate escalation

Webhook endpoint: /webhook/sentinel-incident