The alert actions are utilized by the workflow actions (check out workflow_actions.conf) and dashboards (check out the incident_detail.xml dashboard). However, the actions can be used independently as well. Here is an example of using the alert action independently via SPL to hunt based on an IP address: | makeresults | eval index="YOUR INDEX (defaults to main)", tenant_id="YOUR TENANT ID", query="let ip='IP ADDRESS'; search in (DeviceNetworkEvents, DeviceFileEvents, DeviceLogonEvents, DeviceEvents, EmailEvents, IdentityLogonEvents, IdentityQueryEvents, IdentityDirectoryEvents, CloudAppEvents) Timestamp between (ago(7d) .. now()) and (IPAddress == ip or LocalIP == ip or FileOriginIP == ip or RequestSourceIP == ip or SenderIPv4 == ip or SenderIPv6 == ip or RemoteIP == ip or DestinationIPAddress == ip) | top 100 by Timestamp" | sendalert defender_advanced_hunting The results will be indexed into whatever index you specified. If you do not include the index in the search, results will go in the main index. The sourcetype will be m365:defender:incident:advanced_hunting. Search for the results of the hunting action: index="YOUR INDEX" sourcetype="m365:defender:incident:advanced_hunting" As mentioned, these alert actions are utilized by workflow actions. To observe this, navigate to the Defender 365 Incident Queue dashboard, select an incident (the Incident Detail dashboard should open), select the Entities button in the dashboard, expand the entity, and select Event Actions (see screenshot below). Depending on the entityType field, different actions will appear. Currently, the add-on implements workflow actions for IP addresses, Users, and Files. This can be expanded to other types of entities by editing the workflow_actions.conf file. Still with me? Okay, because there is a different way to get this hunting data. The workflow actions are ad-hoc hunting queries, but you can continuously export all of this table data to an event hub from Defender. Then, use the Splunk Add-on for Microsoft Cloud Services to ingest the data from the event hub. If you go this route, I suggest installing this add-on that maps all of the Defender event hub data to the Common Information Model (CIM) => https://splunkbase.splunk.com/app/5518/
... View more