Getting Data In

TA MS defender not working

titoluna07
Explorer

I have this add-on "TA Microsoft Windows Defender" installed in our UFs using a deployment server, all configuration is the same in all UFs but some of them are working (sending logs to Splunk Cloud) and the others are not.

I can see all servers are successfully sending other eventlog events, system, application, security, but some of them are not sending windows defender logs. Core functionality is working with no errors related to the defender TA as well. 

I have this on windows server 2016. 

Thanks!

 

Labels (2)
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...