microsoft / microsoft/simplechat
Add Microsoft Sentinel plugin support
Open
@paullizer is already working on this.
Since Jun 26, 2026.
enhancement
- Dominant language
- Python
- Stars
- 152
- Forks
- 116
- Avg merge
- 7h 7m
- Merged PRs (30d)
- 122
Description
Summary
Add Microsoft Sentinel action/plugin support on top of Log Analytics KQL querying, with Sentinel-specific tables, saved queries, incidents, entities, and hunting workflows.
User Value
Tracking this as a GitHub issue moves the backlog item out of a private markdown file and gives the team a clear place to prioritize, design, implement, and validate the work.
Proposed Behavior
Decide whether this is a new plugin type or a Sentinel mode of Log Analytics. Include RBAC, workspace id, cloud endpoint, and query safety controls.
Acceptance Criteria
- The requested behavior is designed or implemented for the relevant SimpleChat surfaces.
- Permission, configuration, and existing-feature interactions are accounted for.
- Tests, documentation, or validation notes are added as appropriate.
Notes
- Source backlog entry: Sentinel Plugin
- Source file: priv-simplechat-2/grouped_feature_fix_backlog.md
- Backlog status: New / Extension
- Current anchors:
application/single_app/semantic_kernel_plugins/log_analytics_plugin.py - Proposed roadmap priority: P2
- Proposed roadmap size: L
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.