All Apps and Add-ons

How to fetch Microsoft defender data via Microsoft security Addon?

KulvinderSingh
Path Finder

hi All,

Trying to get data from microsoft security addon and get data for defender.

seems like even after giveing necessary permissions on threat api in azure still not getting the data.

Any help is appreciated

Labels (1)
0 Karma
1 Solution

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

View solution in original post

0 Karma

splunkuser88
Observer

was anyone able to get the Advanced Hunting Results in Microsoft 365 App for Splunk to work?

0 Karma

splunkdIt
Engager

For reference, I created this table that helps identify which MSFT API to configure. It took our team a few attempts to get this right before we had data flowing in for all the sourcetypes - except for advanced hunting (not configured). 

Hope this helps someone in the future 🙂 

SourcetypePermissionInput typeMSFT API 
ms365:defender:incident/ms365:defender:incident:alertIncident.Read.AllModinputMicrosoft Threat Protection
ms:defender:atp:alertsAlert.Read.AllModinputWindowsDefenderATP
ms365:defender:incident/ms365:defender:incident:alertIncident.ReadWrite.AllAlert ActionMicrosoft Threat Protection
m365:defender:incident:advanced_huntingAdvancedHunting.Read.AllAlert ActionMicrosoft Threat Protection
Tags (2)

KulvinderSingh
Path Finder
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @KulvinderSingh,

you have to install the Splunk Add-On for Microsoft Security (https://splunkbase.splunk.com/app/6207) and then follow the configuration steps that you can find at https://docs.splunk.com/Documentation/AddOns/released/MSSecurity/About

beware to the steps on Office365!

Ciao.

Giuseppe

KulvinderSingh
Path Finder

It was firewall blocking the traffic for me.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...