Forum Discussion
AndAufVCG
Nov 19, 2025Brass Contributor
Custom data collection in MDE - what is default?
So you just announced the preview of "Custom data collection in Microsoft Defender for Endpoint (Preview)" which lets me ingest custom data to sentinel. Is there also an overview of what is default ...
ckyalo
Microsoft
Apr 10, 2026DeviceNetworkEvents collection mode is always On and captures Standard network telemetry: TCP/UDP connections, DNS lookups, connection successes/failures and process attribution while DeviceCustomNetworkEvents only captures events you explicitly define with same schema structure, but scoped by your filters.
Additional information on this
DeviceNetworkEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn
Azure Monitor Logs reference - DeviceCustomNetworkEvents - Azure Monitor | Microsoft Learn