<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: the best way to collect Windows Defender logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/677790#M113296</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;you can collect the logs with the following configuration on&amp;nbsp;inputs.conf:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[WinEventLog://Microsoft-Windows-Windows Defender/Operational]
disabled = 0
index = windefender
evt_resolve_ad_obj = 1&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 16 Feb 2024 13:05:38 GMT</pubDate>
    <dc:creator>jcarlosgraca</dc:creator>
    <dc:date>2024-02-16T13:05:38Z</dc:date>
    <item>
      <title>the best way to collect Windows Defender logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656437#M111170</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to collect the logs from Windows Defender and I was looking for an official app and I couldn't find one.&lt;/P&gt;&lt;P&gt;I read some people recommending "TA for Microsoft Windows Defender" but I see that it didn't get update since 2017.&lt;/P&gt;&lt;P&gt;Any other option more recent?&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 13:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656437#M111170</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-09-01T13:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: the best way to collect Windows Defender logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656459#M111171</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234300"&gt;@corti77&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can collect data from Windows Defender using the Splunk Add-On for Windows Security (&lt;A href="https://splunkbase.splunk.com/app/6207" target="_blank"&gt;https://splunkbase.splunk.com/app/6207&lt;/A&gt;) that's also accepted by Microsoft (&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/the-splunk-add-on-for-microsoft-security-is-now-available/ba-p/3171272" target="_blank"&gt;https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/the-splunk-add-on-for-microsoft-security-is-now-available/ba-p/3171272&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 17:00:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656459#M111171</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-01T17:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: the best way to collect Windows Defender logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656495#M111174</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you sure that app includes the basic Microsoft Defender included in any Microsoft OS?&lt;/P&gt;&lt;P&gt;checking the app documentation mentions&amp;nbsp;&lt;SPAN&gt;Microsoft 365 Defender and Defender for Endpoint products.&amp;nbsp; Those are the EDR and SOAR solutions from Microsoft , no mention of the basic AV logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Releasehistory" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/Releasehistory&lt;/A&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2023 09:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656495#M111174</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-09-02T09:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: the best way to collect Windows Defender logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656496#M111175</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234300"&gt;@corti77&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you're right, this Add-on is for the O365 Defender,&lt;/P&gt;&lt;P&gt;but for my little knowledge of Defender (I'm not a fan of it!) and it's possible I'm wrong, it should be possible to have Defender logs from Cloud, using this Add-On.&lt;/P&gt;&lt;P&gt;If it isn't possible, sorry for my wrong answer!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2023 10:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/656496#M111175</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-02T10:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: the best way to collect Windows Defender logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/665656#M111791</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am having this same issue at the moment as the domain i manage is completely airgapped form the internet so no cloud connectivity. After some digging i found have read there are events in the event viewer.&lt;/P&gt;&lt;P&gt;Applications and Services Logs &amp;gt; Microsoft &amp;gt; Windows &amp;gt; Windows Defender &amp;gt; Operational&lt;/P&gt;&lt;P&gt;1116 - MALWAREPROTECTION_STATE_MALWARE_DETECTED&lt;/P&gt;&lt;P&gt;1117 - MALWAREPROTECTION_STATE_MALWARE_ACTION_TAKEN&lt;/P&gt;&lt;P&gt;1118 - MALWAREPROTECTION_STATE_MALWARE_ACTION_FAILED&lt;/P&gt;&lt;P&gt;1119 - MALWAREPROTECTION_STATE_MALWARE_ACTION_CRITICALLY_FAILED&lt;/P&gt;&lt;P&gt;I haven't tested them yet as i have literally just found them online this minute and came across this message board at the same time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps and if you have found anything extra can you put them in here too. Im going set up the forwarder now to collect these and create a dashboard&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;Richard&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 08:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/665656#M111791</guid>
      <dc:creator>RichieOl</dc:creator>
      <dc:date>2023-10-20T08:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: the best way to collect Windows Defender logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/677790#M113296</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;you can collect the logs with the following configuration on&amp;nbsp;inputs.conf:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[WinEventLog://Microsoft-Windows-Windows Defender/Operational]
disabled = 0
index = windefender
evt_resolve_ad_obj = 1&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 16 Feb 2024 13:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-best-way-to-collect-Windows-Defender-logs/m-p/677790#M113296</guid>
      <dc:creator>jcarlosgraca</dc:creator>
      <dc:date>2024-02-16T13:05:38Z</dc:date>
    </item>
  </channel>
</rss>

