<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Defender ATP in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491182#M83933</link>
    <description>&lt;P&gt;I have also been working to get this up and running.  I'd like more detail where you have landed on this.  I can attempt to get Microsoft Office 365 App working but would really like to understand what I am missing in my configuration of the Defender TA and what Splunk support ended up doing.  &lt;/P&gt;

&lt;P&gt;thanks for any additional clarity here.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jan 2020 16:33:10 GMT</pubDate>
    <dc:creator>pmein</dc:creator>
    <dc:date>2020-01-03T16:33:10Z</dc:date>
    <item>
      <title>Windows Defender ATP</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491179#M83930</link>
      <description>&lt;P&gt;I have followed the various sets of instructions for sending Microsoft Defender ATP logs to Splunk, however I am getting the following errors:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;2019-09-30 15:56:57,263 INFO pid=29578&lt;BR /&gt;
tid=MainThread&lt;BR /&gt;
file=connectionpool.py:_new_conn:758 |&lt;BR /&gt;
Starting new HTTPS connection (1):&lt;BR /&gt;
127.0.0.1 2019-09-30 15:57:00,043 INFO pid=29738 tid=MainThread&lt;BR /&gt;
file=connectionpool.py:_new_conn:758 |&lt;BR /&gt;
Starting new HTTPS connection (1):&lt;BR /&gt;
127.0.0.1 2019-09-30 15:57:01,003 INFO pid=29738 tid=MainThread&lt;BR /&gt;
file=connectionpool.py:_new_conn:758 |&lt;BR /&gt;
Starting new HTTPS connection (1):&lt;BR /&gt;
127.0.0.1 2019-09-30 15:57:02,530 INFO pid=29738 tid=MainThread&lt;BR /&gt;
file=connectionpool.py:_new_conn:758 |&lt;BR /&gt;
Starting new HTTPS connection (1):&lt;BR /&gt;
127.0.0.1 2019-09-30 15:57:04,012 INFO pid=29738 tid=MainThread&lt;BR /&gt;
file=connectionpool.py:_new_conn:758 |&lt;BR /&gt;
Starting new HTTPS connection (1):&lt;BR /&gt;
127.0.0.1 2019-09-30 15:57:05,480 INFO pid=29738 tid=MainThread&lt;BR /&gt;
file=splunk_rest_client.py:_request_handler:100&lt;BR /&gt;
| Use HTTP connection pooling&lt;BR /&gt;
2019-09-30 15:57:05,482 INFO pid=29738&lt;BR /&gt;
tid=MainThread&lt;BR /&gt;
file=connectionpool.py:_new_conn:758 |&lt;BR /&gt;
Starting new HTTPS connection (1):&lt;BR /&gt;
127.0.0.1 2019-09-30 15:57:05,497 INFO pid=29738 tid=MainThread&lt;BR /&gt;
file=setup_util.py:log_info:114 |&lt;BR /&gt;
Proxy is not enabled! 2019-09-30&lt;BR /&gt;
15:57:05,884 ERROR pid=29738&lt;BR /&gt;
tid=MainThread&lt;BR /&gt;
file=base_modinput.py:log_error:307 |&lt;BR /&gt;
No JSON object could be decoded&lt;BR /&gt;
2019-09-30 15:57:05,885 ERROR&lt;BR /&gt;
pid=29738 tid=MainThread&lt;BR /&gt;
file=base_modinput.py:log_error:307 |&lt;BR /&gt;
Get error when collecting events.&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;&lt;BR /&gt;
File&lt;BR /&gt;
"/opt/splunk/etc/apps/TA_windows-defender/bin/ta_windows_defender/modinput_wrapper/base_modinput.py",&lt;BR /&gt;
line 127, in stream_events&lt;BR /&gt;
    self.collect_events(ew)   File "/opt/splunk/etc/apps/TA_windows-defender/bin/windows_defender_atp_alerts.py",&lt;BR /&gt;
line 88, in collect_events&lt;BR /&gt;
    input_module.collect_events(self, ew)   File&lt;BR /&gt;
"/opt/splunk/etc/apps/TA_windows-defender/bin/input_module_windows_defender_atp_alerts.py",&lt;BR /&gt;
line 151, in collect_events&lt;BR /&gt;
    "Authorization": 'Bearer ' + access_token, TypeError: cannot&lt;BR /&gt;
concatenate 'str' and 'NoneType'&lt;BR /&gt;
objects&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I've googled, I've read, I've configured, re-configured and configured some more all to no avail.  Is there any catches or tricks to get this to work.  &lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Leigh&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:21:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491179#M83930</guid>
      <dc:creator>balcv</dc:creator>
      <dc:date>2020-09-30T02:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491180#M83931</link>
      <description>&lt;P&gt;I am facing same problem. Did you find a solution?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 04:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491180#M83931</guid>
      <dc:creator>rahulhoney</dc:creator>
      <dc:date>2019-12-12T04:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491181#M83932</link>
      <description>&lt;P&gt;@rahulhoney, I did get the issue resolved however it was through installing and configuring the Microsoft Office 365 App for Splunk and then spending some time on a conference call with our Splunk engineer to get it all up and running.&lt;/P&gt;

&lt;P&gt;Once we had the data from O365, the ATP logs were coming in as part of that.&lt;/P&gt;

&lt;P&gt;Not sure if that helps you, but that's what I've ended up doing.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 00:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491181#M83932</guid>
      <dc:creator>balcv</dc:creator>
      <dc:date>2019-12-16T00:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491182#M83933</link>
      <description>&lt;P&gt;I have also been working to get this up and running.  I'd like more detail where you have landed on this.  I can attempt to get Microsoft Office 365 App working but would really like to understand what I am missing in my configuration of the Defender TA and what Splunk support ended up doing.  &lt;/P&gt;

&lt;P&gt;thanks for any additional clarity here.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 16:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Defender-ATP/m-p/491182#M83933</guid>
      <dc:creator>pmein</dc:creator>
      <dc:date>2020-01-03T16:33:10Z</dc:date>
    </item>
  </channel>
</rss>

