<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defender ATP Add On Settings in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585385#M102994</link>
    <description>&lt;P&gt;I see in the logs that there were 2 alerts returned by the API.&lt;/P&gt;&lt;P&gt;So just make sure you have the right index created. And run the search (index=&amp;lt;defender-atp-index&amp;gt;) in "All Time".&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 15:47:08 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2022-02-16T15:47:08Z</dc:date>
    <item>
      <title>How to configure Defender ATP Add On Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585073#M102950</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Trying to configure the Add-On for Microsoft Defender&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4959/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4959/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Can anyone confirm what settings are needed for:&lt;/P&gt;
&lt;P&gt;Login URL&lt;/P&gt;
&lt;P&gt;Endpoint&lt;/P&gt;
&lt;P&gt;Resource?&lt;/P&gt;
&lt;P&gt;Whichever I use, I'm getting 401 errors. Have followed&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide&lt;/A&gt;&amp;nbsp;and confirmed the permissions on the App registration are 100% correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 15:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585073#M102950</guid>
      <dc:creator>baz</dc:creator>
      <dc:date>2022-02-16T15:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Defender ATP Add On Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585257#M102978</link>
      <description>&lt;P&gt;The error code 401 clearly describes the issue with permission. Please recheck the permission.&lt;/P&gt;&lt;TABLE border="1" width="1019px" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Input&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;API&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;Permission&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;Sourcetype&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;Reference&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.2px"&gt;Microsoft 365 Defender Incidents (input)&lt;/TD&gt;&lt;TD width="173.775px"&gt;Microsoft Threat Protection&lt;/TD&gt;&lt;TD width="201.262px"&gt;(Application) Incident.Read.All&lt;/TD&gt;&lt;TD width="321.825px"&gt;m365:defender:incident&lt;/TD&gt;&lt;TD width="239.212px"&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender/api-hello-world?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender/api-hello-world?view=o365-worldwide&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.2px"&gt;Defender Advanced Hunting (action)&lt;/TD&gt;&lt;TD width="173.775px"&gt;Microsoft Threat Protection&lt;/TD&gt;&lt;TD width="201.262px"&gt;(Application) AdvancedHunting.Read.All&lt;/TD&gt;&lt;TD width="321.825px"&gt;m365:defender:incident:advanced_hunting&lt;/TD&gt;&lt;TD width="239.212px"&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender/api-advanced-hunting?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender/api-advanced-hunting?view=o365-worldwide&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.2px"&gt;Defender Update Incident (action)&lt;/TD&gt;&lt;TD width="173.775px"&gt;Microsoft Threat Protection&lt;/TD&gt;&lt;TD width="201.262px"&gt;(Application) Incident.ReadWrite.All&lt;/TD&gt;&lt;TD width="321.825px"&gt;N/A&lt;/TD&gt;&lt;TD width="239.212px"&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender/api-update-incidents?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender/api-update-incidents?view=o365-worldwide&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.2px"&gt;Microsoft Defender for Endpoint Alerts (input)&lt;/TD&gt;&lt;TD width="173.775px"&gt;WindowsDefenderATP&lt;/TD&gt;&lt;TD width="201.262px"&gt;(Application) Alert.Read.All&lt;/TD&gt;&lt;TD width="321.825px"&gt;ms:defender:atp:alerts&lt;/TD&gt;&lt;TD width="239.212px"&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please make sure you are using the same App credentials that have the permission as I've done similar mistakes.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;------&lt;/P&gt;&lt;P&gt;Please accept the solution if this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 04:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585257#M102978</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-16T04:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Defender ATP Add On Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585278#M102981</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;Thanks for your response!&lt;/P&gt;&lt;P&gt;Permissions are fine, running through that test script in the knowledge base&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide" target="_blank"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide&lt;/A&gt;&amp;nbsp;is also fine and I can pull results.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 06:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585278#M102981</guid>
      <dc:creator>baz</dc:creator>
      <dc:date>2022-02-16T06:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Defender ATP Add On Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585280#M102983</link>
      <description>&lt;P&gt;Further Update, now getting logins successfully, with the below but nothing into Splunk&lt;BR /&gt;&lt;BR /&gt;2022-02-16 06:53:51,353 DEBUG pid=23770 tid=MainThread file=base_modinput.py:log_debug:288 | get access token called&lt;BR /&gt;2022-02-16 06:53:51,353 DEBUG pid=23770 tid=MainThread file=base_modinput.py:log_debug:288 | Token genrated last time:2022-02-16 06:53:08.758148&lt;BR /&gt;2022-02-16 06:53:51,353 DEBUG pid=23770 tid=MainThread file=base_modinput.py:log_debug:288 | Token elapsed time(in seconds): 42&lt;BR /&gt;2022-02-16 06:53:51,353 INFO pid=23770 tid=MainThread file=setup_util.py:log_info:117 | Proxy is not enabled!&lt;BR /&gt;2022-02-16 06:53:51,353 DEBUG pid=23770 tid=MainThread file=base_modinput.py:log_debug:288 | Proxies set is : {}&lt;BR /&gt;2022-02-16 06:53:51,353 DEBUG pid=23770 tid=MainThread file=base_modinput.py:log_debug:288 | Global SSL Verify settings is: False&lt;BR /&gt;2022-02-16 06:53:51,354 DEBUG pid=23770 tid=MainThread file=connectionpool.py:_new_conn:959 | Starting new HTTPS connection (1): api.securitycenter.microsoft.com:443&lt;BR /&gt;2022-02-16 06:53:52,122 DEBUG pid=23770 tid=MainThread file=connectionpool.py:_make_request:437 | &lt;A href="https://api.securitycenter.microsoft.com:443" target="_blank"&gt;https://api.securitycenter.microsoft.com:443&lt;/A&gt; "GET //api/alerts?sinceTimeUtc=2022-02-09%2006:53:51.350605 HTTP/1.1" 200 2167&lt;BR /&gt;2022-02-16 06:53:52,124 INFO pid=23770 tid=MainThread file=base_modinput.py:log_info:295 | Number of alerts returned: 2&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 06:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585280#M102983</guid>
      <dc:creator>baz</dc:creator>
      <dc:date>2022-02-16T06:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Defender ATP Add On Settings</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585385#M102994</link>
      <description>&lt;P&gt;I see in the logs that there were 2 alerts returned by the API.&lt;/P&gt;&lt;P&gt;So just make sure you have the right index created. And run the search (index=&amp;lt;defender-atp-index&amp;gt;) in "All Time".&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 15:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Defender-ATP-Add-On-Settings/m-p/585385#M102994</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-16T15:47:08Z</dc:date>
    </item>
  </channel>
</rss>

