Forum Discussion

alexturkin's avatar
alexturkin
Copper Contributor
Sep 02, 2021

Do Microsoft Defender for Identity SIEM logs conform to CEF format?

Microsoft Defender for Identity SIEM log reference page says "Alerts and events are in the CEF format."   CEF spec Version 25 (I used one from that page: https://community.microfocus.com/cyberres/p...
  • EliOfek's avatar
    EliOfek
    Sep 02, 2021
    Effectively, yes, if you want to use a "pure" CEF format, then RFC3164 will work better for you.
    It's main disadvantage is that it does not support Unicode, only ASCII.
    And yes, the technical writes of ATA used the RFC3164 for samples there (or a mix), but I advise not to rely on ATA docs for MDI reference, as things often work differently between the two and it might be confusing.

Resources