- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Windows Defender Endpoint / ATP via Azure Event Hub
pcookhayboo
Explorer
01-27-2021
08:23 AM
I'm using the Splunk Addon for Microsoft Cloud Service to import our ATP / Microsoft Defender Endpoint Data into Splunk. I've succeeded into getting the data in but the events aren't getting separated correctly. Below is a screenshot of a single event. Each Record should be an individual Splunk event.
My question is should the Splunk Addon for Microsoft Cloud Service automatically parse this out or is this something I should work through in the props.conf and linebreaks.
Here's the information I used to set this up:
- ATP to EventHub: https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/raw-data-...
- Event Hub to Splunk: https://www.splunk.com/en_us/blog/platform/splunking-azure-event-hubs.html
