Hello all,
I am trying to setup the Microsoft 365 Defender Add-on for Splunk (https://splunkbase.splunk.com/app/4959/) to collect events from gcc.securitycenter.microsoft.us but I am not really seeing an option to change the endpoint. Can this be configured to hit https://api-gcc.securitycenter.microsoft.us?
Hi @_joe
specs doesn't really have much about changing it, you can check the same under README dir inside add-on. if you wish to change you have to edit the python code , input_module_microsoft_365_defender_incidents.py file having the some urls' hard-coded based on environment gov/non-gov etc. Try if that helps and review other .py files and give a try.
--
An upvote would be appreciated if this reply helps!