Forum Discussion
AndrewX
May 18, 2022Iron Contributor
SecurityAlert doesn't include important alert details
In the MS 365 Defender, we have an alert generated on "Granted mailbox permission" activity. This event shows up in the SecurityEvent and OfficeActivity $tables, over in Log Analytics. In Office...
GaryBushey
May 18, 2022Bronze Contributor
I'm saying the new data connector will copy the information from Defender and put into MS Sentinel so you can write the query to return all the data you want in it
AndrewX
May 18, 2022Iron Contributor
Apologies, but i don't see that. The data in the alert is only half of what is in Defender?
Or are you saying that i get half of the data from the alert, then pivot/join to the OfficeActivity table and get the rest from there?
Or are you saying that i get half of the data from the alert, then pivot/join to the OfficeActivity table and get the rest from there?
- GaryBusheyMay 19, 2022Bronze ContributorIf there isn't enough data in your alert, you can change the alert rule to add the additional data from the other M365 tables that the new data connector ingests