Microsoft Sentinel's Thinkst Canary solution lets you ingest Canary alerts directly into your Microsoft Sentinel workspace using the Thinkst Canary data connector.
Once connected, Canary alerts are ingested into Sentinel and can be used with the included analytics rule to automatically create Microsoft Sentinel incidents now in the Microsoft Defender portal.
This guide walks through installing the Thinkst Canary solution, connecting your Canary Console, creating the analytics rule, and confirming that Canary incidents are appearing in Microsoft Sentinel.
Prerequisites
Before starting, make sure you have:
- A Microsoft Sentinel workspace.
- Read and write permissions to the Microsoft Sentinel workspace.
- Access to your Thinkst Canary Console.
- A Canary Console Read-only API key.
Step 1: Install the Thinkst Canary solution
- Log in to the Microsoft Defender portal and open:
Microsoft Sentinel > Content management > Content hub- Search for:
Thinkst- Select the Thinkst Canary solution.
- Click Install.
Once installation completes, the solution will contain the Thinkst Canary data connector and the Canary alerts to incidents analytics rule template.
Step 2: Get your Canary Console Domain Hash and API key
The Microsoft Sentinel connector requires your Canary Console Domain Hash and an API key.
For example, if your Canary Console URL is:
https://abc1234.canary.tools
your Domain Hash is:
abc1234
Enter only the hash in Microsoft Sentinel, rather than the complete .canary.tools hostname.
In your Canary Console, open Global Settings, go to API and create or copy a Read-Only API key for use with the Sentinel connector.
Step 3: Configure the Thinkst Canary data connector
- Return to the installed Thinkst Canary solution in the Microsoft Sentinel Content hub.
- Select the Thinkst Canary data connector.
- Click Open connector page.
Under Configuration, enter:
Canary Console Domain: yourhash
API Authentication Token: <your Canary API key>
- Click Connect.
Once the connection has completed successfully, the connector status should display Connected.
Step 4: Create the Canary alerts to incidents analytics rule
The Thinkst Canary solution includes an analytics rule template that can turn incoming Canary alerts into Microsoft Sentinel incidents.
- Return to:
Microsoft Sentinel > Content management > Content hub > Thinkst Canary
- Select Canary alerts to incidents.
- Click Create rule.
Configure the rule
The rule template will populate the rule name, description, severity, MITRE ATT&CK mappings and rule query.
Review the settings and click Next: Set rule logic.
The supplied query uses the ThinkstCanaryIncidents_CL table and filters out Canary operational events that should not result in Sentinel incidents.
By default, event grouping is configured to Trigger an alert for each event.
- Review the rule logic and continue through the wizard.
On the Review + create page, confirm that validation passes, then click Save.
Step 5: Confirm Canary incidents are being created
Once the connector is receiving data and the analytics rule is enabled, incoming Canary alerts will be available to Microsoft Sentinel and matching alerts will create incidents.
Head to:
Microsoft Defender > Incidents
Canary activity should now appear in the incident queue.
That's it! Your Canary Console is now connected to Microsoft Sentinel, with Canary alerts available for investigation through Microsoft Sentinel incidents.
Troubleshooting
If the connector does not connect, first confirm that:
- The Canary Console Domain contains only your Domain Hash and not the complete
.canary.toolshostname. - The API key is valid.
- Your Microsoft Sentinel workspace permissions meet the prerequisites shown on the connector page.
If you're still having trouble, please contact Canary Support and we'll be happy to help.