# Microsoft Sentinel Threat Intelligence Uploads STIX 2.0/2.1 threat-intelligence objects to a Microsoft Sentinel workspace via the [Threat Intelligence Upload API](https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api). :::info The Sentinel Threat Intelligence Upload API is in **Preview** upstream. It's a different endpoint from the [Microsoft Sentinel](./msft-sentinel-v2) log ingestion output — different host, different auth scope, different payload shape (STIX). Use this output for threat intel; use the Sentinel v2 output for logs. ::: ## Overview Records are wrapped into the STIX upload envelope and sent to Sentinel Threat Intelligence. Supported STIX object types: `indicator`, `attack-pattern`, `threat-actor`, `identity`, `relationship`. Records should already be in STIX 2.0/2.1 shape — map upstream inputs (Mandiant, AlienVault OTX, etc.) to STIX with a transform node before this output. ## Requirements - A Microsoft Sentinel–enabled Log Analytics workspace, and its **workspace ID** (GUID). - A Microsoft Entra (Azure AD) application registration with a client secret. - The application must be assigned the **Microsoft Sentinel Contributor** role at the workspace scope. See Microsoft's [prerequisites](https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api#prerequisites). ## Setup 1. In the Azure portal, register an application in Microsoft Entra ID and create a client secret. Note the **Tenant ID**, **Client ID**, and **Client Secret**. 2. In your Log Analytics workspace → **Access control (IAM)** → **Add role assignment**, assign **Microsoft Sentinel Contributor** to the application. 3. Copy the workspace GUID from the workspace overview page. ## Configuration ### Settings | Setting | Type | Required | Description | |---------|------|----------|-------------| | Workspace ID | string (UUID) | Yes | The Log Analytics workspace ID (GUID) that will store the STIX objects. | | Source System | string | Yes | Free-form label identifying the source system in Sentinel. Must not be the literal string `Microsoft Sentinel` — that value is restricted by the API. | | Tenant ID | string | Yes | The Microsoft Entra tenant (directory) ID. | | Client ID | string | Yes | The application (client) ID registered in Microsoft Entra. | ### Secrets | Secret | Type | Required | Description | |--------|------|----------|-------------| | Client Secret | string | Yes | The client secret for the registered Microsoft Entra application. | ## Record shape Each record forwarded to this output must be a valid STIX 2.0/2.1 domain object. For example, an indicator record: ```json { "type": "indicator", "spec_version": "2.1", "id": "indicator--", "created": "2026-01-01T00:00:00.000Z", "modified": "2026-01-01T00:00:00.000Z", "pattern": "[ipv4-addr:value = '1.2.3.4']", "pattern_type": "stix", "valid_from": "2026-01-01T00:00:00.000Z" } ``` See the [STIX 2.1 Indicator spec](https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html#_muftrcpnf89v) for required fields and pattern syntax. ## Limits The Sentinel Threat Intelligence Upload API enforces these caps (see [throttling limits](https://learn.microsoft.com/en-us/azure/sentinel/stix-objects-api#throttling-limits-for-the-api)): - **100 STIX objects per request** — Monad batches to this size automatically. - **100 requests per minute** per user. - Practical ceiling of roughly 10,000 objects per minute before requests are throttled. ## Troubleshooting - **`source_system "Microsoft Sentinel" is restricted`**: pick any other label — the literal `Microsoft Sentinel` is reserved by the API. - **401 Unauthorized**: verify the client secret is current and the app has the **Microsoft Sentinel Contributor** role at the workspace scope. - **404 Workspace not found**: confirm the workspace ID is the GUID of a Sentinel-enabled Log Analytics workspace. - **Records rejected with per-record errors**: the response reports a `recordIndex` and validation message per bad record. Successful records in the same batch are already published; fix the offending records upstream (usually a missing STIX required field or malformed `pattern`). - **429 Rate limit exceeded**: reduce upstream throughput; Monad honors the API's retry hint automatically. - **Indicators don't appear in Sentinel**: Sentinel's Threat Intelligence blade can take a few minutes to reflect newly uploaded objects. ## Related Articles - [Connect your TIP with the upload API](https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-upload-api) - [Import threat intelligence with the upload API](https://learn.microsoft.com/en-us/azure/sentinel/stix-objects-api) - [STIX 2.1 specification](https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html)