All Apps and Add-ons

I'm looking for an app that pulls al windows defender logs from Azure to splunk

ftonen
Explorer

I have found two apps this one and this one, but the first one only pulls security alerts and for the other one you need to deploy the app to the servers. Thing is, we also need the clients info and they don't have forwarders installed.

Is there an app that pulls all windows defender logs from Azure?

0 Karma

ftonen
Explorer

Woops, I forgot to link the apps: https://splunkbase.splunk.com/app/4128/ (only security alerts) and https://splunkbase.splunk.com/app/3734/#/details (not on workstation clients).

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...