All Apps and Add-ons

Installing the Microsoft 365 Defender Add-on for GCC

_joe
Contributor

Hello all,

I am trying to setup the Microsoft 365 Defender Add-on for Splunk (https://splunkbase.splunk.com/app/4959/) to collect events from gcc.securitycenter.microsoft.us but I am not really seeing an option to change the endpoint.  Can this be configured to hit https://api-gcc.securitycenter.microsoft.us?

 

 

 

 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @_joe 

specs doesn't really have much about changing it, you can check the same under README dir inside add-on. if you wish to change you have to edit the python code , input_module_microsoft_365_defender_incidents.py file having the some  urls' hard-coded based on environment gov/non-gov etc. Try if that helps and review other .py files and give a try.

--

An upvote would be appreciated if this reply helps!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...