Jul 29 2024 09:23 PM - edited Jul 29 2024 09:30 PM
Is there a way to stream logs from Microsoft Defender for Endpoint to a Log Analytics Workspace, which will then be shared or shipped to another Log Analytics Workspace (different Tenant).
Any links or tutorials are welcome.
Jul 31 2024 01:10 AM
@ProtoProto678 Did you look at the streaming API for Defender? You could send data to a storage account or Event Hub and process from there. Alternatively, if you have Sentinel, you could leverage the Defender for Endpoint connector, and then the data will end up in the Sentinel Log Analytics Workspace (if you don't have Sentinel, forget what I just said - I would then go with the streaming API)
Jul 31 2024 04:29 PM
thanks for the info. I will look at this connector and see if this is possible for the usecase. I have not looked at the Streaming API. Thank you.