- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Microsoft 365 Defender add-on for splunk
VijaySrrie
Builder
12-15-2021
07:19 PM
Hi,
This add-on is to ingest MCAS logs into splunk?
Or do we need to use syslog collectors to ingest the MCAS logs? and this add-on is to only ingest incidents and alserts?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
venkatasri

SplunkTrust
12-15-2021
07:53 PM
Hi @VijaySrrie
Read this the description talk about MCAS however this doesn't do ingest them just for CIM - https://splunkbase.splunk.com/app/5278/
MCAS logs you would probably need syslog/ Splunk TCP/UDP to ingest.
Microsoft 365 Defender add-on as per the docs it ingest only Incidents & Alerts.
---
An upvote would be appreciated if this reply helps!
