I have setup Microsoft defender for endpoint inputs with many add on but It looks as though most of the add on are not CIM ready for Endpoint and Malware Data model.
I have used Microsoft 365 Defender Add-on for Splunk - https://splunkbase.splunk.com/app/4959/
Splunk Add-on for Microsoft Security - https://splunkbase.splunk.com/app/6207/#/overview
Which one is CIM ready?
I have used