All Apps and Add-ons

Azure Microsoft Windows Defender data receiving error message

pmein
Explorer

I have the Add-on for Windows Defender installed and configured. I am seeing that it appears to be polling for events successfully.

Log event in _internal:

file=connectionpool.py:_make_request:400 | https://wdatp-alertexporter-eu.securitycenter.windows.com:443 "GET //api/alerts?sinceTimeUtc=2019-12-26%2013:34:57.241814 HTTP/1.1" 200 2236

I have triggered an alert and see it within the ATP portal and also received the email alert form Azure but I am not seeing the data in Splunk.

Looking at _internal I do see the log entry:

DEBUG pid=91667 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/ATP_EVENTS_obj_checkpoint HTTP/1.1" 404 140

Why is the 404 error coming across? What am I missing in my configuration? I thought I followed the docs correctly but I must be missing something.

0 Karma

pmein
Explorer

I would also ask if anyone has this up and running with Splunk to pull the ATP alerts from Microsoft Defender Security Center. I would certainly be interested in any hurdles you encountered or did it just work out of the gate for you.

0 Karma

siemguy
Observer

Hello, were you able to get this working using the API? I was told the best option would be through SCCM. 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...