Microsoft Defender ATP (MDATP) events can be sent to a blob storage account or an Event Hub. I was wondering if anyone is collecting MDATP events either way and how the setup was to parse the events?
Thx
I ended up using the Microsoft Azure Add on for Splunk (https://splunkbase.splunk.com/app/3757/), which was straight forward and easy to configure.
I ended up using the Microsoft Azure Add on for Splunk (https://splunkbase.splunk.com/app/3757/), which was straight forward and easy to configure.
Please take a look at this app : https://splunkbase.splunk.com/app/5038/ you can onboard the data using the Modular inputs.
Thx for the link, but this add-on is only collecting MDATP alerts and not the actual events