Exporting MDE logs to Log Analytics Workspace - Is there a way or this cannot be done?

Copper Contributor

Is there a way to stream logs from Microsoft Defender for Endpoint to a Log Analytics Workspace, which will then be shared or shipped to another Log Analytics Workspace (different Tenant).

 

Any links or tutorials are welcome. 

 

 

2 Replies

@ProtoProto678 Did you look at the streaming API for Defender? You could send data to a storage account or Event Hub and process from there. Alternatively, if you have Sentinel, you could leverage the Defender for Endpoint connector, and then the data will end up in the Sentinel Log Analytics Workspace (if you don't have Sentinel, forget what I just said - I would then go with the streaming API)

@AndrePKI 

thanks for the info. I will look at this connector and see if this is possible for the usecase. I have not looked at the Streaming API. Thank you.