Setup Guide
This guide walks you through connecting Microsoft Sentinel to the ELLIO Threat Intelligence TAXII feed.
Step 1: Get Your TAXII Credentials
- Log in to the ELLIO Platform.
- Open Data Feeds → Connectors and pick Microsoft Sentinel (TAXII).
- Generate TAXII credentials - you'll receive a username and password.
- Note your assigned collection ID.
Step 2: Enable the TAXII Data Connector in Sentinel
- In the Azure portal, navigate to your Microsoft Sentinel workspace
- Go to Content Hub and search for Threat Intelligence
- Install the Threat Intelligence solution if not already installed
- Go to Data connectors and find Threat Intelligence - TAXII
- Click Open connector page
Step 3: Configure the TAXII Connection
Click Add new and fill in the following fields:
| Field | Value |
|---|---|
| Friendly name | ELLIO Threat Intelligence |
| API root URL | https://taxii-sentinel.integrations.ellio.tech/ellio/ |
| Collection ID | Your assigned collection ID from Step 1 |
| Username | Your TAXII username from Step 1 |
| Password | Your TAXII password from Step 1 |
| Import indicators | At most one month old (recommended) or All available for initial import |
| Polling frequency | Once an hour or Once a day |