Splunk Enterprise Security

Splunk Add on for Microsoft ATP Endpoint: Which add-ons are CIM ready?

Loves-to-Learn Everything

I have setup Microsoft defender for endpoint inputs with many add on but It looks as though most of the add on are not CIM ready for Endpoint and Malware Data model.

I have used  Microsoft 365 Defender Add-on for Splunk - https://splunkbase.splunk.com/app/4959/

Splunk Add-on for Microsoft Security - https://splunkbase.splunk.com/app/6207/#/overview


Which one is CIM ready?




I have used edr.JPG

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...