Getting Data In

How best to ingest Microsoft Defender ATP events?

jwalzerpitt
Influencer

Microsoft Defender ATP (MDATP) events can be sent to a blob storage account or an Event Hub. I was wondering if anyone is collecting MDATP events either way and how the setup was to parse the events?

Thx

Labels (3)
0 Karma
1 Solution

jwalzerpitt
Influencer

I ended up using the Microsoft Azure Add on for Splunk (https://splunkbase.splunk.com/app/3757/), which was straight forward and easy to configure.

View solution in original post

0 Karma

jwalzerpitt
Influencer

I ended up using the Microsoft Azure Add on for Splunk (https://splunkbase.splunk.com/app/3757/), which was straight forward and easy to configure.

0 Karma

iamkilarunaresh
Explorer

Please take a look at this app : https://splunkbase.splunk.com/app/5038/ you can onboard the data using the Modular inputs. 

0 Karma

jwalzerpitt
Influencer

Thx for the link, but this add-on is only collecting MDATP alerts and not the actual events 

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...