<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending On-Prem Windows Defender AV DATA to On Splunk in Security</title>
    <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559336#M12409</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234967"&gt;@tarungupta0311&lt;/a&gt;&amp;nbsp;other one here - little outdated -&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3734/" target="_blank"&gt;TA for Microsoft Windows Defender | Splunkbase&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 02:20:06 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-07-14T02:20:06Z</dc:date>
    <item>
      <title>Sending On-Prem Windows Defender AV DATA to On Splunk</title>
      <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559334#M12407</link>
      <description>&lt;P&gt;How to send&amp;nbsp;On-Prem Windows Defender AV DATA to On Splunk&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 02:04:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559334#M12407</guid>
      <dc:creator>tarungupta0311</dc:creator>
      <dc:date>2021-07-14T02:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Sending On-Prem Windows Defender AV DATA to On Splunk</title>
      <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559335#M12408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234967"&gt;@tarungupta0311&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried this add-on&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/5038/#/details" target="_blank"&gt;Add-on for Microsoft Defender ATP Known As Windows Defender ATP | Splunkbase&lt;/A&gt;&amp;nbsp;developer supported not official with Splunk.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if this reply helps!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 02:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559335#M12408</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-14T02:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sending On-Prem Windows Defender AV DATA to On Splunk</title>
      <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559336#M12409</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234967"&gt;@tarungupta0311&lt;/a&gt;&amp;nbsp;other one here - little outdated -&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3734/" target="_blank"&gt;TA for Microsoft Windows Defender | Splunkbase&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 02:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559336#M12409</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-14T02:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sending On-Prem Windows Defender AV DATA to On Splunk</title>
      <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559342#M12411</link>
      <description>&lt;P&gt;This is for ATP not for the old legacy windows defender AV&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 03:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559342#M12411</guid>
      <dc:creator>tarungupta0311</dc:creator>
      <dc:date>2021-07-14T03:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sending On-Prem Windows Defender AV DATA to On Splunk</title>
      <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559343#M12412</link>
      <description>&lt;P&gt;This is not useful when Windows Defender data is going to a Database.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 03:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559343#M12412</guid>
      <dc:creator>tarungupta0311</dc:creator>
      <dc:date>2021-07-14T03:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sending On-Prem Windows Defender AV DATA to On Splunk</title>
      <link>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559399#M12415</link>
      <description>&lt;P&gt;Solution - If you want to&amp;nbsp;Send On-Prem Windows Defender AV DATA to On Splunk, we need to send it to&amp;nbsp; Splunk Enterprise via DB Connect.&lt;BR /&gt;Also below solution will work when we are doing Windows Authentication against the database, please follow the below steps, on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Ubuntu&lt;/STRONG&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to set up the connection&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Follow the steps&amp;nbsp;@&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/DBX/3.5.1/ReleaseNotes/Releasenotes" target="_blank" rel="noopener nofollow noreferrer"&gt;https://docs.splunk.com/Documentation/DBX/3.5.1/ReleaseNotes/Releasenotes&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;install DB Connect&amp;nbsp;DBX 3.4.2 software via Splunkbase, or browse more apps and download from there.&lt;/LI&gt;&lt;LI&gt;Now it comes to installing Java on Splunk DB-Connect,&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;1st check if java is already installed on the server, for that type java – version, if java is not installed follow&lt;/LI&gt;&lt;LI&gt;Run&amp;nbsp;&lt;BR /&gt;sudo apt update&amp;nbsp;&lt;BR /&gt;sudo apt install default-jre&lt;BR /&gt;sudo apt install openjdk-11-jre-headless&lt;/LI&gt;&lt;LI&gt;Validate Java is installed and running in server mode with&amp;nbsp;java -version&amp;nbsp;It should look something like this:&lt;/LI&gt;&lt;/OL&gt;&lt;/UL&gt;&lt;P&gt;$ java -version openjdk version "11.0.7" 2020-04-14 OpenJDK Runtime Environment (build 11.0.7+10-post-Ubuntu-3ubuntu1) OpenJDK 64-Bit&amp;nbsp;&lt;STRONG&gt;Server VM&lt;/STRONG&gt;&amp;nbsp;(build 11.0.7+10-post-Ubuntu-3ubuntu1, mixed mode, sharing)&lt;/P&gt;&lt;UL&gt;&lt;OL&gt;&lt;LI&gt;Set the JAVA_HOME Environment Variable&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;OpenJDK 11 is located at&amp;nbsp;/usr/lib/jvm/java-11-openjdk-amd64&lt;/LI&gt;&lt;LI&gt;Set the variable globally by adding&amp;nbsp;JAVA_HOME="/usr/lib/jvm/java-11-openjdk-amd64"&amp;nbsp;to&amp;nbsp;/etc/environment.&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Save and exit VIM&lt;/LI&gt;&lt;LI&gt;Type reboot to reboot the Ubuntu machine.&lt;/LI&gt;&lt;LI&gt;Now Access to Db Connect – Configuration – settings – General – in JRE Installation Path, enter&lt;BR /&gt;/usr/lib/jvm/java-11-openjdk-amd64&lt;/LI&gt;&lt;LI&gt;Hit Save and let DB Connect Ap detect the JAVA.&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Now it comes for Java Drivers&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Since you have installed java version 11, we need to install Java Drivers 11&lt;/LI&gt;&lt;LI&gt;Install 8.2.1 already tested JDBC Ms Generic Driver from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/sql/connect/jdbc/release-notes-for-the-jdbc-driver?view=sql-server-ver15#previous-releases" target="_blank" rel="noopener nofollow noreferrer"&gt;https://docs.microsoft.com/en-us/sql/connect/jdbc/release-notes-for-the-jdbc-driver?view=sql-server-...&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Install JTDC JDBC drivers from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://sourceforge.net/projects/jtds/files/" target="_blank" rel="noopener nofollow noreferrer"&gt;https://sourceforge.net/projects/jtds/files/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(link is mentioned in Splunk Documentation)&lt;/LI&gt;&lt;LI&gt;Both are required as for Windows Authentication we will be doing a mix of them&lt;/LI&gt;&lt;LI&gt;Now Access to Db Connect – Configuration – settings – Drivers – Click Reload and you should see 8.2 Generic and 1.3 JTDS drivers&lt;/LI&gt;&lt;LI&gt;Reboot the Splunk Ubuntu Server.&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Now it comes to Setting up the Identity in DB Connection – Configuration – Database – Identities&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Identity Name – Any user-friendly name&lt;/LI&gt;&lt;LI&gt;Username – Account which will have access to the Database&lt;/LI&gt;&lt;LI&gt;Password – Password of that account&lt;/LI&gt;&lt;LI&gt;Check Use Windows Authentication Domain&lt;/LI&gt;&lt;LI&gt;Enter the Domain&lt;/LI&gt;&lt;LI&gt;Hit Save&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Now it comes to Setting up the Connection in DB Connection – Configuration – Database – Connections&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;This is the most tricky part&lt;/LI&gt;&lt;LI&gt;Connection Name – Any user-friendly name&lt;/LI&gt;&lt;LI&gt;Identity – Select the account, which will do authentication against a database&lt;/LI&gt;&lt;LI&gt;Connection Type – MS-SQL Server Using JTDS Driver with Windows Authentication&lt;/LI&gt;&lt;LI&gt;Timezone – appropriate Timezone&lt;/LI&gt;&lt;LI&gt;JDBC URL Setting&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;Enter the manauyl&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;JDBC URL - jdbc:jtds:sqlserver://serverIP:1433/databasename;useCursors=true;domain=domainname;useNTLMv2=true&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Advance Read only - checked&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Now Make a database connection and send it to the Index created on Splunk Cloud.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 14 Jul 2021 11:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Sending-On-Prem-Windows-Defender-AV-DATA-to-On-Splunk/m-p/559399#M12415</guid>
      <dc:creator>tarungupta0311</dc:creator>
      <dc:date>2021-07-14T11:53:12Z</dc:date>
    </item>
  </channel>
</rss>

