Azure Microsoft Defender Endpoint: How to Integrate or Stream Logs to Azure Log Analytics Workspace

Arnold Reddy 0 Reputation points
2024-07-30T00:51:02.96+00:00

I'm having trouble finding articles on how to stream/connect logs from Microsoft Defender for Endpoint to a new Log Analytics Workspace in the same tenant. Most solutions I've found show Defender for Cloud, but we're using Microsoft Defender for Endpoint and need to send logs to a Log Analytics Workspace in the same tenant in Part 1, then to another LA workspace in another tenant for Part 2. I think Log Ingestion API could be the solution, but I'm looking for examples or usable tutorials. Can anyone share some information or advice?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,048 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
30 questions
0 comments No comments
{count} votes