Getting Data In

TA MS defender not working


I have this add-on "TA Microsoft Windows Defender" installed in our UFs using a deployment server, all configuration is the same in all UFs but some of them are working (sending logs to Splunk Cloud) and the others are not.

I can see all servers are successfully sending other eventlog events, system, application, security, but some of them are not sending windows defender logs. Core functionality is working with no errors related to the defender TA as well. 

I have this on windows server 2016. 



Labels (2)
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!