<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is my azure not sending all Windows Defender for Enpoint Alerts to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-azure-not-sending-all-Windows-Defender-for-Enpoint/m-p/557178#M92203</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I try to figure this out for a week now and I am stucked. I installed the Microsoft 365 Defender Add-on for Splunk, which is the official supported TA referring to the Microsoft Partner docs.&lt;BR /&gt;&lt;BR /&gt;I enabled the input for endpoint alerts and excepted the TA to index all alerts since the "start time" (2 weeks ago).&lt;BR /&gt;&lt;BR /&gt;But only one event was send, the earliest event in the 14 days period. So in my case an event from 6/9/2021, the input was enabled on 23rd of June.&lt;BR /&gt;&lt;BR /&gt;Splin internal is only telling me that the connection was successfull ( status 200) and how long it took.&lt;BR /&gt;&lt;BR /&gt;I double checked all the siem intergration docs from microsoft , like what permissions need to be set and so on.&lt;BR /&gt;&lt;BR /&gt;Here is the link &lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Does anyone know, if there are more options in azure that need to be turned on to make it more talkativ?&lt;BR /&gt;&lt;BR /&gt;In Defender itself I can see way more alerts than 1 in the last 14 days.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 11:46:54 GMT</pubDate>
    <dc:creator>dkeck</dc:creator>
    <dc:date>2021-06-25T11:46:54Z</dc:date>
    <item>
      <title>Why is my azure not sending all Windows Defender for Enpoint Alerts to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-azure-not-sending-all-Windows-Defender-for-Enpoint/m-p/557178#M92203</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I try to figure this out for a week now and I am stucked. I installed the Microsoft 365 Defender Add-on for Splunk, which is the official supported TA referring to the Microsoft Partner docs.&lt;BR /&gt;&lt;BR /&gt;I enabled the input for endpoint alerts and excepted the TA to index all alerts since the "start time" (2 weeks ago).&lt;BR /&gt;&lt;BR /&gt;But only one event was send, the earliest event in the 14 days period. So in my case an event from 6/9/2021, the input was enabled on 23rd of June.&lt;BR /&gt;&lt;BR /&gt;Splin internal is only telling me that the connection was successfull ( status 200) and how long it took.&lt;BR /&gt;&lt;BR /&gt;I double checked all the siem intergration docs from microsoft , like what permissions need to be set and so on.&lt;BR /&gt;&lt;BR /&gt;Here is the link &lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/api-hello-world?view=o365-worldwide&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Does anyone know, if there are more options in azure that need to be turned on to make it more talkativ?&lt;BR /&gt;&lt;BR /&gt;In Defender itself I can see way more alerts than 1 in the last 14 days.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 11:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-azure-not-sending-all-Windows-Defender-for-Enpoint/m-p/557178#M92203</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2021-06-25T11:46:54Z</dc:date>
    </item>
  </channel>
</rss>

