Microsoft Defender for Cloud
Cloud and workloads

Stream alerts to monitoring solutions

In brief

The page now separates PowerShell and Azure portal setup paths, labels Splunk- and QRadar-specific guidance, updates reference links, and clarifies Microsoft Graph Security API alert streaming and related content.

What Defender admins need to know

No administrator action is required. The revised guidance makes existing SIEM integration procedures easier to follow.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Stream alerts to monitoring solutions

Configure ingestion of all audit logs into Microsoft Sentinel

Another alternative for investigatingYou can also investigate Defender for Cloud alerts in Microsoft Sentinel is to streamby streaming your audit logs into Microsoft Sentinel:

Stream alerts to QRadar and Splunk

To export security alerts to Splunk and QRadar, you need to use Event Hubs and a built-in connector. You can either use a PowerShell script or the Azure portal to set up the requirements for exporting security alerts for your subscription or tenant. Once the requirements are in place, you need to use the procedure specific to each SIEM to install the solutionconnector in your SIEM platform by following the SIEM platform.QRadar or Splunk steps described later in this article.

Prerequisites

PowerShell script (Recommended)

To set up the Azure services with a PowerShell script, follow these steps:

  1. Download and run the Defender for Cloud third-party SIEM integration PowerShell scripts.

  2. Enter the required parameters.

Azure portal

To create the required resources in the Azure portal, follow these steps:

  1. Sign in to the Azure portal.

  2. Search for and select Event Hubs.

  3. Copy and save the connection string to the account to use in QRadar.

For more detailed instructions,instructions about QRadar setup, see Prepare Azure resources for exporting to Splunk and QRadar.

If you're streaming alerts to Splunk:

  1. Give permissions to the Microsoft Entra Application to read from the event hub you created before.

For more detailed instructions,instructions about Splunk setup, see Prepare Azure resources for exporting to Splunk and QRadar.

Connect the event hub to your preferred solution using the built-in connectors

Tool Hosted in Azure Description
IBM QRadar No The Microsoft Azure DSM and Microsoft Azure Event Hubs Protocol are available for download from the IBM QRadar DSM guide for Microsoft Azure platform.
Splunk No Splunk Add-on for Microsoft Cloud Services is an open source project available in Splunkbase.

If you can't install an add-on in your Splunk instance, for example if you're using a proxy or running on Splunk Cloud, you can forward these events to the Splunk HTTP Event Collector using Azure Function For Splunk, which is triggered by new messages in the event hub.

Stream alerts with continuous export

To stream alerts with continuous export:

  1. Enable continuous export:

  2. Connect the event hub to your preferred solution using the built-in connectors: | SumoLogic | No | Instructions for setting up SumoLogic to consume data from an event hub are available at Collect Logs for the Azure Audit App from Event Hubs. | | ArcSight | No | The ArcSight Azure Event Hubs smart connector is available as part of the ArcSight smart connector collection. | | Syslog server | No | If you want to stream Azure Monitor data directly to a syslog server, you can use a solution based on an Azure function.| | LogRhythm | No| Instructions to set up LogRhythm to collect logs from an event hub are available at Six tips for securing your Azure cloud environment.| |Logz.io | Yes | For more information, see Getting started with monitoring and logging using Logz.io for Java apps running on Azure| |Dynatrace | No | For instructions to set up the integration in Dynatrace, read Ingest Microsoft Defender for Cloud security events

Use the Microsoft Graph Security API to stream alerts to non-Microsoft applications

Defender for Cloud's includes a built-in integration with Microsoft Graph Security API that lets you stream alerts without the need of any further configuration requirements.

You can use this API to stream alerts from your entire tenant (and data from many Microsoft Security products) into non-Microsoft SIEMs and other popular platforms:

Next stepsRelated content

This page explained how to ensure your MicrosoftFor more information about streaming Defender for Cloud alert data is available in youralerts to SIEM, SOAR, orand ITSM tool of choice. For related material,solutions, see: