Hi folks, I am trying to get Defender logs into the Splunk Add-On for Microsoft Security but I am struggling a bit. It "appears" to be configured correctly but I am seeing this error in the logs: ERROR pid=222717 tid=MainThread file=ms_security_utils.py:get_atp_alerts_odata:261 | Exception occurred while getting data using access token : HTTPSConnectionPool(host='api.securitycenter.microsoft.com', port=443): Max retries exceeded with url: /api/alerts?$expand=evidence&$filter=lastUpdateTime+gt+2024-05-22T12:34:35Z (Caused by ConnectTimeoutError(<urllib3.connection.HTTPSConnection object at 0x7fe514fa1bd0>, 'Connection to api.securitycenter.microsoft.com timed out. (connect timeout=60)')) Is this an issue with the way the Azure Connector App is permissioned or something else entirely? Thanks in advance
... View more