Deployment Architecture

How can we ingest MDI logs to Splunk?

RishavAnand
New Member

How can we ingest MDI logs to Splunk?

Labels (1)
0 Karma

dsctm3
Path Finder

If you are trying to find the alerts coming from Microsoft Defender for Identity, you can gather the alerts via the MS Graph Plugin found here:

https://splunkbase.splunk.com/app/4564#Configuring-Microsoft-Graph-Security-data-inputs

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What are MDI logs?

Where are they stored?

Do you have Splunk forwarders on there too?

There are a lot of unanswered questions about your environment and the potential ways that data can be ingested into Splunk. Have you ingested other data sources?

Can you modify these to include the MDI logs?

0 Karma

RishavAnand
New Member

"Splunk forwarders" are installed on the servers where MDI sensor is installed. 

So far, no ingestion has been done.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So, you need to configure the inputs for the forwarders so that they know where to look for the MDI logs

https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/Admin/IntroGDI

 

0 Karma

RishavAnand
New Member

MDI logs are generated on security.microsoft.com portal and are not present locally on the servers where Splunk forwarders and MDI sensor are installed. There is a possibility with Sentinel [ https://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration ] but we want to do this to Splunk. 

We might not be able to install anything on the portal. Do we have a set of documentation available as to how to send the MDI logs from security.microsoft.com portal to Splunk ?

0 Karma

jconger
Splunk Employee
Splunk Employee

To get Microsoft Defender XDR data into Splunk, use the Splunk Add-on for Microsoft Security => https://splunkbase.splunk.com/app/6207

All the Microsft Defender XDR incidents, alerts, entities, evidence, etc. are collected by this add-on.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...