Forward Alerts from a Secondary Sentinel to a Primary Sentinel Workspace Using Logic Apps

Madhan R 0 Reputation points
2025-12-04T05:12:56.1466667+00:00

HI,

I am exploring the feasibility of forwarding Microsoft Sentinel alerts from a Secondary sentinel Workspace to a Primary Sentinel Workspace. There are two Sentinels for two LAWs and now we want to forward the alerts in One sentinel (secondary) to another (primary), so that we can monitor from that workspace itself.
I would like guidance on the following:

Best approach to forward alerts between two Sentinel workspaces

Whether using Logic Apps + Log Analytics Data Collector API is the recommended method

Required permissions and configuration for the managed identity or service principal

Any limitations or considerations when forwarding cross-workspace Sentinel alerts

Sample Logic App workflows or REST API examples (if available)

If anyone has implemented a similar cross-workspace Sentinel alert forwarding setup, your inputs or references to documentation would be greatly appreciated.

Thanks in advance!

Microsoft Security | Microsoft Sentinel
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.