AI integration connects directly to the Entity Behavior Analytics (UEBA) engine and the underlying SecurityInsights table in your Sentinel Log Analytics workspace. The primary architectural touchpoints are:
- Entity Timeline API: To retrieve and analyze sequences of activities (logins, file accesses, network connections) for a given user or host over days or weeks.
- Hunting Bookmarks & Watchlists: To store AI-generated hypotheses about anomalous behavior patterns for further investigation.
- Incident Comments & Custom Details: To inject AI-summarized behavioral context directly into Sentinel incidents, enriching the analyst's view.




