All Apps and Add-ons

Installing the Microsoft 365 Defender Add-on for GCC

_joe
Contributor

Hello all,

I am trying to setup the Microsoft 365 Defender Add-on for Splunk (https://splunkbase.splunk.com/app/4959/) to collect events from gcc.securitycenter.microsoft.us but I am not really seeing an option to change the endpoint.  Can this be configured to hit https://api-gcc.securitycenter.microsoft.us?

 

 

 

 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @_joe 

specs doesn't really have much about changing it, you can check the same under README dir inside add-on. if you wish to change you have to edit the python code , input_module_microsoft_365_defender_incidents.py file having the some  urls' hard-coded based on environment gov/non-gov etc. Try if that helps and review other .py files and give a try.

--

An upvote would be appreciated if this reply helps!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...