@12980401
Thank you for your post and I apologize for the delayed response!
When looking more into your issue, I understand that you're having troubles collecting data from Microsoft Azure Event Hub after integrating it with Microsoft Defender. Please keep in mind that after integration, the data collection could take some time (~1hr) and if you're still having issues after waiting, you should be able to verify that the events are being exported to the Event Hubs by running the Advanced Hunting query below.
Select Hunting > Advanced Hunting > Query and enter the following query:
//This query will show you how many emails were received in the last hour joined across all the other tables.
EmailEvents
|join kind=fullouter EmailAttachmentInfo on NetworkMessageId
|join kind=fullouter EmailUrlInfo on NetworkMessageId
|join kind=fullouter EmailPostDeliveryEvents on NetworkMessageId
|where Timestamp > ago(1h)
|count
For more info: Verify that the events are being exported to the Event Hubs
Additional Links:
I hope this helps!
If you're still having issues and would like to work closely with our support team, please let me know.
Thank you for your time and patience throughout this issue.
If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.