All Apps and Add-ons

How to fetch Microsoft defender data via Microsoft security Addon?

KulvinderSingh
Path Finder

hi All,

Trying to get data from microsoft security addon and get data for defender.

seems like even after giveing necessary permissions on threat api in azure still not getting the data.

Any help is appreciated

Labels (1)
0 Karma
1 Solution

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

View solution in original post

0 Karma

splunkuser88
Observer

was anyone able to get the Advanced Hunting Results in Microsoft 365 App for Splunk to work?

0 Karma

splunkdIt
Engager

For reference, I created this table that helps identify which MSFT API to configure. It took our team a few attempts to get this right before we had data flowing in for all the sourcetypes - except for advanced hunting (not configured). 

Hope this helps someone in the future 🙂 

SourcetypePermissionInput typeMSFT API 
ms365:defender:incident/ms365:defender:incident:alertIncident.Read.AllModinputMicrosoft Threat Protection
ms:defender:atp:alertsAlert.Read.AllModinputWindowsDefenderATP
ms365:defender:incident/ms365:defender:incident:alertIncident.ReadWrite.AllAlert ActionMicrosoft Threat Protection
m365:defender:incident:advanced_huntingAdvancedHunting.Read.AllAlert ActionMicrosoft Threat Protection
Tags (2)

KulvinderSingh
Path Finder
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @KulvinderSingh,

you have to install the Splunk Add-On for Microsoft Security (https://splunkbase.splunk.com/app/6207) and then follow the configuration steps that you can find at https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/About

beware to the steps on Office365!

Ciao.

Giuseppe

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

0 Karma
Get Updates on the Splunk Community!

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...