<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to find sourcetype=&amp;quot;ms365:defender:incident:alerts&amp;quot;? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616800#M11111</link>
    <description>&lt;P&gt;Ok so you should at least to which indexes your MDE logs are going no?&lt;BR /&gt;The thing is that you first be able to find your MDE logs via a classic Splunk search, and then retrieve what is the sourcetype assigned to those logs.&lt;BR /&gt;&lt;BR /&gt;Finally, try to change the MDE App Dashboard by modifying the sourcetype used there.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 10:12:46 GMT</pubDate>
    <dc:creator>GaetanVP</dc:creator>
    <dc:date>2022-10-12T10:12:46Z</dc:date>
    <item>
      <title>Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616496#M11096</link>
      <description>&lt;P&gt;Unable to find sourcetype="ms365:defender:incident:alerts"&lt;BR /&gt;&lt;BR /&gt;can u pls help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 13:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616496#M11096</guid>
      <dc:creator>Gaikwad</dc:creator>
      <dc:date>2022-10-10T13:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616562#M11099</link>
      <description>&lt;P&gt;Please provide more information.&amp;nbsp; Where do you see this message?&amp;nbsp; What were you doing at the time?&amp;nbsp; Have you installed the proper add-on for the sourcetype?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 17:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616562#M11099</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-10T17:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616595#M11100</link>
      <description>&lt;P&gt;I'm trying to setup Microsoft 365 app for Splunk in that app -&amp;gt;Security-&amp;gt; defender -&amp;gt; Defender 365 overview dashboard. this dashboard is not working&lt;/P&gt;&lt;P&gt;when I check the query it contains &amp;nbsp;&lt;SPAN&gt;sourcetype="ms365:defender:incident:alerts" but same&amp;nbsp;I'm unable to find it when&amp;nbsp;I search for index = azure or index= main&lt;BR /&gt;&lt;BR /&gt;as&amp;nbsp;I check add is already there, only concern is unable to find that&amp;nbsp;sourcetype="ms365:defender:incident:alerts"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;so just want to know, if that source type is not there then is there a way&amp;nbsp;available so we&amp;nbsp;can configure that or any other solution is&amp;nbsp;available &amp;nbsp;?&lt;BR /&gt;&lt;BR /&gt;thanks&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 05:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616595#M11100</guid>
      <dc:creator>Gaikwad</dc:creator>
      <dc:date>2022-10-11T05:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616684#M11104</link>
      <description>&lt;P&gt;I just installed that app and don't see the same error message even though I have no ms365 data on my system.&amp;nbsp; By default, the dashboards in the app search index=* so they should be able to find the data if it exists.&lt;/P&gt;&lt;P&gt;Generally, when a sourcetype is not there it's because no data with that soucetype has been indexed.&amp;nbsp; Check your inputs and verify you have the appropriate add-on installed both on your indexers and search heads.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 14:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616684#M11104</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-11T14:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616778#M11107</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;thanks for your reply&lt;BR /&gt;&lt;BR /&gt;as I check in input is not setup for&amp;nbsp;sourcetype="ms365:defender:incident:alerts"?&lt;BR /&gt;&lt;BR /&gt;can you please let me know, how can I setup input for this &amp;nbsp;"ms365:defender:incident:alerts"&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 07:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616778#M11107</guid>
      <dc:creator>Gaikwad</dc:creator>
      <dc:date>2022-10-12T07:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616783#M11108</link>
      <description>&lt;P data-unlink="true"&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Do you receive the MDE logs via an Azure Event Hub ? If it's the case the sourcetype of MDE logs could be "mscs:azure:eventhub".&lt;BR /&gt;&lt;BR /&gt;Maybe if you just change the sourcetype specified in the MDE App Dashboard you could see some data.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sourcetype="mscs:azure:eventhub"&lt;/LI-CODE&gt;&lt;P data-unlink="true"&gt;Or maybe you would need to rename sourcetype of your incoming MDE events.&lt;BR /&gt;&lt;BR /&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 08:05:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616783#M11108</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2022-10-12T08:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616784#M11109</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I tried to search those logs&amp;nbsp;index =* sourcetype="mscs:azure:eventhub"&lt;BR /&gt;&lt;BR /&gt;but no luck&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 08:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616784#M11109</guid>
      <dc:creator>Gaikwad</dc:creator>
      <dc:date>2022-10-12T08:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to find sourcetype="ms365:defender:incident:alerts"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616800#M11111</link>
      <description>&lt;P&gt;Ok so you should at least to which indexes your MDE logs are going no?&lt;BR /&gt;The thing is that you first be able to find your MDE logs via a classic Splunk search, and then retrieve what is the sourcetype assigned to those logs.&lt;BR /&gt;&lt;BR /&gt;Finally, try to change the MDE App Dashboard by modifying the sourcetype used there.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 10:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-find-sourcetype-quot-ms365-defender-incident-alerts/m-p/616800#M11111</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2022-10-12T10:12:46Z</dc:date>
    </item>
  </channel>
</rss>

