Microsoft 365 Defender Event Collector
Deprecated. Use 'Office 365' in the XSIAM Data Sources instead.
- Category
- Analytics & SIEM
- Pack
- MicrosoftDefenderAdvancedThreatProtection
Configuration parameters
- endpoint_type — Endpoint Type
- tenant_id — Tenant ID (required)
- client_id — Client (Application) ID (required)
- credentials — (required)
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- fetch_timeout — Fetch alerts timeout
- limit — Number of alerts for each fetch.
- isFetchEvents — Fetch events
- url — Server URL (e.g., https://api.securitycenter.microsoft.com)
- verify — Verify SSL Certificate
- proxy — Use system proxy settings
Commands (2)
- microsoft-365-defender-auth-reset — Run this command if for some reason you need to rerun the authentication process.
- microsoft-365-defender-get-events — Returns a list of alerts.