All Apps and Add-ons

How to fetch Microsoft defender data via Microsoft security Addon?

KulvinderSingh
Path Finder

hi All,

Trying to get data from microsoft security addon and get data for defender.

seems like even after giveing necessary permissions on threat api in azure still not getting the data.

Any help is appreciated

Labels (1)
0 Karma
1 Solution

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

View solution in original post

0 Karma

splunkuser88
Observer

was anyone able to get the Advanced Hunting Results in Microsoft 365 App for Splunk to work?

0 Karma

splunkdIt
Engager

For reference, I created this table that helps identify which MSFT API to configure. It took our team a few attempts to get this right before we had data flowing in for all the sourcetypes - except for advanced hunting (not configured). 

Hope this helps someone in the future 🙂 

SourcetypePermissionInput typeMSFT API 
ms365:defender:incident/ms365:defender:incident:alertIncident.Read.AllModinputMicrosoft Threat Protection
ms:defender:atp:alertsAlert.Read.AllModinputWindowsDefenderATP
ms365:defender:incident/ms365:defender:incident:alertIncident.ReadWrite.AllAlert ActionMicrosoft Threat Protection
m365:defender:incident:advanced_huntingAdvancedHunting.Read.AllAlert ActionMicrosoft Threat Protection
Tags (2)

KulvinderSingh
Path Finder
0 Karma

gcusello
Esteemed Legend

Hi @KulvinderSingh,

you have to install the Splunk Add-On for Microsoft Security (https://splunkbase.splunk.com/app/6207) and then follow the configuration steps that you can find at https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/About

beware to the steps on Office365!

Ciao.

Giuseppe

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...