All Apps and Add-ons

How to fetch Microsoft defender data via Microsoft security Addon?

KulvinderSingh
Path Finder

hi All,

Trying to get data from microsoft security addon and get data for defender.

seems like even after giveing necessary permissions on threat api in azure still not getting the data.

Any help is appreciated

Labels (1)
0 Karma
1 Solution

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

View solution in original post

0 Karma

splunkuser88
Observer

was anyone able to get the Advanced Hunting Results in Microsoft 365 App for Splunk to work?

0 Karma

splunkdIt
Engager

For reference, I created this table that helps identify which MSFT API to configure. It took our team a few attempts to get this right before we had data flowing in for all the sourcetypes - except for advanced hunting (not configured). 

Hope this helps someone in the future 🙂 

SourcetypePermissionInput typeMSFT API 
ms365:defender:incident/ms365:defender:incident:alertIncident.Read.AllModinputMicrosoft Threat Protection
ms:defender:atp:alertsAlert.Read.AllModinputWindowsDefenderATP
ms365:defender:incident/ms365:defender:incident:alertIncident.ReadWrite.AllAlert ActionMicrosoft Threat Protection
m365:defender:incident:advanced_huntingAdvancedHunting.Read.AllAlert ActionMicrosoft Threat Protection
Tags (2)

KulvinderSingh
Path Finder
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @KulvinderSingh,

you have to install the Splunk Add-On for Microsoft Security (https://splunkbase.splunk.com/app/6207) and then follow the configuration steps that you can find at https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/About

beware to the steps on Office365!

Ciao.

Giuseppe

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...