Splunk Enterprise Security

Splunk Add on for Microsoft ATP Endpoint: Which add-ons are CIM ready?

chidiuchegbu
Loves-to-Learn Everything

I have setup Microsoft defender for endpoint inputs with many add on but It looks as though most of the add on are not CIM ready for Endpoint and Malware Data model.

I have used  Microsoft 365 Defender Add-on for Splunk - https://splunkbase.splunk.com/app/4959/

Splunk Add-on for Microsoft Security - https://splunkbase.splunk.com/app/6207/#/overview

 

Which one is CIM ready?

 

 

 

I have used edr.JPG

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...