Forum Discussion
james1987
Mar 16, 2023Occasional Reader
Not all network events are on DeviceNetworkEvents table
Anyone know how network event are being collected in MS Defender for Endpoint. Look like DeviceNetworkEvents does not have all network events. We did a testing using nslookup. Do a nslookup to domain...
HA13029
Jun 19, 2024Brass Contributor
Hello,
First, thanks a lot for your help.
I also find that without Real time protection/RTP enabled, most of the traffic is not logged...
Regards,
HA
First, thanks a lot for your help.
I also find that without Real time protection/RTP enabled, most of the traffic is not logged...
Regards,
HA
jbmartin6
Jun 20, 2024Iron Contributor
OH, that is interesting, we haven't noticed that. It might explain some weird things we saw in the lab though, I will check it out.