Microsoft Defender for Cloud
Cloud and workloads

Set up continuous export in the Azure portal

In brief

Updated the setup heading and anchor, clarified how vulnerability assessment findings are included, and specified export destinations and the separate CSV alert export guidance.

What Defender admins need to know

Administrators can use the clearer instructions when configuring continuous exports; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Learn more about [Azure Monitor and Log Analytics workspace solutions](/previous-versions/azure/azure-monitor/insights/solutions).

Set upCreate a continuous export in the Azure portalconfiguration

You can set up continuous export in the Microsoft Defender for Cloud pages in the Azure portal, by using the REST API, or at scale by using Azure Policy templates.

- **Streaming**. Assessments are sent when a resource’s health state is updated (if no updates occur, no data is sent).
- **Snapshots**. A snapshot of the current state of the selected data types that are sent once a week per subscription. To identify snapshot data, look for the field **IsSnapshot**.

If your selection includes one of these recommendations, you can include the vulnerability assessment findings with them:those recommendations:

- [SQL databases should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/82e20e14-edc5-4373-bfc4-f13121257c37)
- [SQL servers on machines should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/f97aa83c-9b63-4f9a-99f6-b22c4398f936)
- [Machines should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/1195afff-c881-495e-9bc5-1486211ae03f)
- [System updates should be installed on your machines](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/4ab6e3c5-74dd-8b35-9ab9-f61b30875b27)

To include thevulnerability assessment findings with thesethe preceding vulnerability-related recommendations, set **Include security findings** to **Yes**.

:::image type="content" source="./media/continuous-export/include-security-findings-toggle.png" alt-text="Screenshot that shows the Include security findings toggle in a continuous export configuration." :::

Related content

In this article, you learnedThe preceding steps showed how to configure continuous exportsexport of yourDefender for Cloud recommendations and alerts. You also learned howalerts to download your alerts data as a Log Analytics workspace or an event hub. For one-time CSV file.export of alerts, see download a CSV file.

To see related content: