Azure Defender

Carolina Zamisnicu 316 Reputation points
2021-09-29T14:26:54.577+00:00

Hi,

How can I see all the logs that my Azure Defender is creating?
Also, is there any possibility to visualize them in Azure Event Hubs?
Thank you!

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,202 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 34,066 Reputation points Microsoft Employee
    2021-09-29T20:27:13.14+00:00

    Yes. You can view these logs in Azure Sentinel, Azure Event Hubs, Event Viewer, and Log Analytics.

    You can enable Azure Defender for your Event Hubs resources and then forward any logs from Event Hubs to your Azure Sentinel.

    Follow this guide to set up streaming to a dedicated Azure Event Hub.

    See also:
    Connect Azure Defender alerts from Azure Security Center:
    Configure Microsoft Defender ATP Logs in the Eventhub
    How to collect all Microsoft Defender ATP events

    Let me know if this helps!


0 additional answers

Sort by: Most helpful