Microsoft Defender XDR
Developer and API

Streaming Api

In brief

The streaming API documentation now refers to configuring Microsoft Defender, instead of Microsoft Defender XDR, to stream Advanced Hunting events to Azure Event Hubs or Azure storage.

What Defender admins need to know

No administrator action is required; the setup guidance and destinations are unchanged.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Topic Description
Stream events to Azure Event Hubs Learn about enabling the streaming API in your tenant and configure Microsoft Defender XDR to stream Advanced Hunting to Event Hubs.
Stream events to your Azure storage account Learn about enabling the streaming API in your tenant and configure Microsoft Defender XDR to stream Advanced Hunting to your Azure storage account.
Supported event types Learn which Advanced Hunting event types the Streaming API supports.

Watch this short video to learn how to set up the streaming API to ship event information directly to Azure Event hubs for consumption by visualization services, data processing engines, or Azure storage for long-term data retention.