Forum Discussion
FrankM670
Sep 26, 2019Copper Contributor
Azure ATP alerts from MCAS and Graph
Hi, for my current customer we are trying to integrate O365 ATP and Azure ATP alerts into their current SIEM. we have enabled the MCAS integration for Azure ATP. this enables us to get the security ...
FrankM670
Sep 30, 2019Copper Contributor
Thanks for that! is there a list of those ID's that we van map back to an Alert? like there is for the externalID in the syslog messages? as i assume it is still not advised to filter on descriptions as these might be updated.
thanks.
Segun160
Feb 17, 2020Copper Contributor
FrankM670 Did you manage to solve this ? can you please help with how you did ?
- Astrid McCleanFeb 18, 2020Former Employee
All the unique ids have now been documented here: https://docs.microsoft.com/en-us/azure-advanced-threat-protection/suspicious-activity-guide?tabs=external#security-alert-name-mapping-and-unique-external-ids
See the Cloud App Security IDs tab for the names you see via MCAS and the Graph API.