Microsoft Defender XDR
General

Integrate your SIEM tools with Microsoft Defender XDR

In brief

The article now explains pulling incidents through REST APIs and streaming event data through Azure Event Hubs to supported SIEM platforms. It also clarifies terminology for Splunk CIM mapping and the ArcSight SmartConnector, which replaces the retired FlexConnector.

What Defender admins need to know

Administrators can use the updated guidance to select an integration method and connector for supported SIEM platforms.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate your SIEM tools with Microsoft Defender XDR

[!INCLUDE Microsoft Defender XDR rebranding]

This article describes how to integrate supported security information and event management (SIEM) tools with Microsoft Defender XDR. You can pull incidents through the REST API or stream event data through Azure Event Hubs to platforms such as Splunk, ArcSight, Elastic, and IBM QRadar.

PullUse SIEM tools to pull Microsoft Defender incidents and streaming event data using security information and events management (SIEM) tools

Using the new, fully supported Splunk Add-on for Microsoft Security that supports:

  • Ingesting incidents that contain alerts from the following products, which are mapped onto Splunk's Common Information Model (CIM), a standard schema for normalizing event data:

    • Microsoft Defender
    • Microsoft Defender for Endpoint

Ingest incidents into Micro Focus ArcSight

The new SmartConnector for Microsoft Defender XDR ingests incidents into ArcSight and maps thesethe incident data onto its Common Event Framework (CEF).

For more information on the new ArcSight SmartConnector for Microsoft Defender XDR, see ArcSight Product Documentation.

The SmartConnector replaces the previous FlexConnector for Microsoft Defender for Endpoint that'sEndpoint, which is now retired.

Ingest incidents into Elastic

Related content

[!INCLUDE Microsoft Defender XDR rebranding]