Hi,
This add-on is to ingest MCAS logs into splunk?
Or do we need to use syslog collectors to ingest the MCAS logs? and this add-on is to only ingest incidents and alserts?
Hi @VijaySrrie
Read this the description talk about MCAS however this doesn't do ingest them just for CIM - https://splunkbase.splunk.com/app/5278/
MCAS logs you would probably need syslog/ Splunk TCP/UDP to ingest.
Microsoft 365 Defender add-on as per the docs it ingest only Incidents & Alerts.
---
An upvote would be appreciated if this reply helps!