Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community

Native windows 10 defender events to Azure sentinel

Copper Contributor

Thanks in advance.

I can't see the Windows Defender logs (the system one) in Azure Sentinel
In the agent configuration I have added the branch: Microsoft-Windows-Windows Defender / Operational
As I do with Sysmon, but I don't see the events, for example when I disable online protection.

Can you think of what could be happening?

Thanks !!!

PS: is there any query where I can verify the "schema" that I have configured in the Windows agents, apart from seeing it graphically?

All the best

0 Replies