IBM QRadar cannot receiving RiskLevel and RiskState information from Microsoft Graph API

Davin Ardian 1 Reputation point
2022-09-27T14:26:26.263+00:00

Hello everyone,

Hope you are all is going well.

we already collected logs/events from Microsoft Graph API but we are not receiving RiskState and RiskLevel information
245129-image.png

The QRadar by default gathers the logs from URL : https://graph.microsoft.com/v1.0/security/alerts on the QRadar event paylod we are receiving RiskScore but the value is sometimes none.

Does anyone experience the same issue?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
{count} votes