Microsoft Defender for Cloud Event Collector
XSIAM collector for Microsoft Defender for Cloud alerts.
- Category
- Analytics & SIEM
- Pack
- AzureSecurityCenter
Configuration parameters
- server_url — Microsoft Azure Management URL
- client_id — (required)
- tenant_id — (required)
- enc_key — (required)
- certificate_thumbprint —
- private_key — Private Key
- sub_id — (required)
- first_fetch — First fetch time interval
- unsecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (2)
- ms-defender-for-cloud-auth-reset — Run this command if for some reason you need to rerun the authentication process.
- ms-defender-for-cloud-get-events — Lists alerts for the subscription according to the specified filters.