Need ATP integration with Phantom documentation

Mridula Mishra 1 Reputation point
2020-09-09T19:29:59.16+00:00

Hi Team,

Can someone share some document for integrating ATP with phantom automation platform?

Thanks
Mridula

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,311 Reputation points Microsoft Employee
    2020-09-10T04:05:32.95+00:00

    @Mridula Mishra
    Microsoft ATP currently supports IBM QRadar and Micro Focus ArcSight through a dedicated SIEM integration model.

    If you are talking about Splunk's Phantom, that is supported by a different integration model based on the new Alert API.

    1) For the integration you will have to login to : https://df.securitycenter.microsoft.com/interoperability/partners and look for splunk :

    23687-1.png

    2) Once selected you would need to download the ATP Add-on for Splunk :

    23724-2.png

    Once done, you would need to import that data from splunk to Phantom.

    -----------------------------------------------------------------------------------------------------------------

    If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.