Microsoft Defender for Cloud Apps
Cloud and workloads

Create snapshot cloud discovery reports

In brief

The article now explicitly describes creating a snapshot report by manually uploading firewall or proxy traffic logs to validate the log format and gain initial cloud app visibility before using the automatic log collector.

What Defender admins need to know

Administrators have clearer guidance on the recommended preparation and workflow for snapshot reports.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create snapshot cloud discovery reports

Create a Cloud Discovery snapshot report

It's important to upload a log manually and let Microsoft Defender for Cloud Apps parse it before trying to use the automatic log collector. For information on how the log collector works and the expected log format, including required traffic log attributes and conditions, see Using traffic logs for cloud discovery later.

This article explains how to create a Cloud Discovery snapshot report in this article.Microsoft Defender for Cloud Apps by manually uploading traffic logs from your firewall or proxy. Use a snapshot report to validate your log format and get initial visibility into cloud app usage before setting up the automatic log collector.

If you don't have a log yet and you want to see an example of what your log should look like, download a sample log file. Follow the snapshot report creation procedure to see what your log should look like.