The Splunk Add-on for Microsoft Security is now available

Published Feb 17 2022 10:17 AM 4,159 Views
Microsoft

We're happy to share that the Splunk-supported Splunk Add-on for Microsoft Security is now available. This add-on builds on the Microsoft 365 Defender Add-on for Splunk 1.3.0 and maps the Microsoft Defender for Endpoint Alerts API properties or the Microsoft 365 Defender Incidents API properties onto Splunk's Common Information Model (CIM).

 

The Splunk Add-on for Microsoft Security only supports ingesting Alerts or Incidents into Splunk - customers should continue using the Microsoft 365 Defender Add-on for Splunk 1.3.0 App or the Splunk SOAR Windows Defender ATP App to manage/update Alerts or Incidents (assignedTo, classification, determination, status, and comments fields) directly from Splunk.

The Splunk SOAR Windows Defender ATP App 3.5.2 supports 30 additional Microsoft Defender for Endpoint API calls (see Additional Information below).

 

Additional Information:

 

The Microsoft Defender for Endpoint Team

%3CLINGO-SUB%20id%3D%22lingo-sub-3171272%22%20slang%3D%22en-US%22%3EThe%20Splunk%20Add-on%20for%20Microsoft%20Security%20is%20now%20available%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3171272%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20happy%20to%20share%20that%20the%20Splunk-supported%20%3CFONT%20color%3D%22%230000FF%22%3E%3CA%20title%3D%22The%20Splunk-supported%20Add-on%20for%20Microsoft%20365%20Defender%20Incidents%20API%20or%20Microsoft%20Defender%20for%20Endpoint%20Alerts%20API%22%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F6207%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ESplunk%20Add-on%20for%20Microsoft%20Security%3C%2FA%3E%3C%2FFONT%3E%20is%20now%20available.%20This%20add-on%20builds%20on%20the%20%3CFONT%20color%3D%22%230000FF%22%3E%3CA%20title%3D%22The%20Microsoft%20365%20Defender%20Add-on%20for%20Splunk%20supports%20Microsoft%20365%20Defender%20Incidents%20API%20or%20Microsoft%20Defender%20for%20Endpoint%20Alerts%20API%22%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F4959%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20365%20Defender%20Add-on%20for%20Splunk%201.3.0%3C%2FA%3E%3C%2FFONT%3E%26nbsp%3Band%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%26nbsp%3Bmaps%20the%20%3CA%20title%3D%22Microsoft%20Defender%20for%20Endpoint%20Alerts%20API%20schema%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender-endpoint%2Falerts%3Fview%3Do365-worldwide%23properties%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Defender%20for%20Endpoint%20Alerts%20API%20properties%3C%2FA%3E%26nbsp%3Bor%20the%20%3CA%20title%3D%22Microsoft%20365%20Defender%20Incidents%20API%20schema%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender%2Fapi-list-incidents%3Fview%3Do365-worldwide%23incident-metadata%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20365%20Defender%20Incidents%20API%20properties%3C%2FA%3E%20onto%20Splunk's%20Common%20Information%20Model%20(CIM).%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22direction%3A%20ltr%3B%22%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3EThe%20Splunk%20Add-on%20for%20Microsoft%20Security%20only%20supports%20ingesting%20Alerts%20or%20Incidents%20into%20Splunk%20-%20customers%20should%20continue%20using%20the%20Microsoft%20365%20Defender%20Add-on%20for%20Splunk%201.3.0%20App%20or%20the%20%3CA%20title%3D%22The%20Splunk%20SOAR%20Windows%20Defender%20ATP%20App%22%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F5870%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ESplunk%20SOAR%20Windows%20Defender%20ATP%20App%3C%2FA%3E%20to%20manage%2F%3C%2FSPAN%3Eupdate%20Alerts%20or%20Incidents%26nbsp%3B%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E(assignedTo%2C%20classification%2C%20determination%2C%20status%2C%20and%20comments%20fields)%20%3C%2FSPAN%3Edirectly%20from%20Splunk.%3C%2FP%3E%0A%3CP%20style%3D%22direction%3A%20ltr%3B%22%3EThe%20Splunk%20SOAR%20Windows%20Defender%20ATP%20App%203.5.2%20supports%2030%20additional%20Microsoft%20Defender%20for%20Endpoint%20API%20calls%20(see%20Additional%20Information%20below).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAdditional%20Information%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CFONT%20face%3D%22inherit%22%3EThe%20Splunk%20documentation%20for%20the%20%3CA%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F6207%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ESplunk%20Add-on%20for%20Microsoft%20Security%3C%2FA%3E%20is%20%3C%2FFONT%3Eavailable%3CFONT%20face%3D%22inherit%22%3E%26nbsp%3Bhere%3A%26nbsp%3B%3CBR%20%2F%3E%3C%2FFONT%3E%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fdocs.splunk.com%2FDocumentation%2FAddOns%2Freleased%2FMSSecurity%2FAbout%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.splunk.com%2FDocumentation%2FAddOns%2Freleased%2FMSSecurity%2FAbout%3C%2FA%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3ESplunk%20provide%20guidance%20on%20migrating%20from%20the%20%3CA%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F4959%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EMicrosoft%20365%20Defender%20Add-on%20for%20Splunk%20version%201.3.0%3C%2FA%3E%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F6207%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ESplunk%20Add-on%20for%20Microsoft%20Security%3C%2FA%3E%20here%3A%3CBR%20%2F%3E%3C%2FSPAN%3E%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fdocs.splunk.com%2FDocumentation%2FAddOns%2Freleased%2FMSSecurity%2FMigrate%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.splunk.com%2FDocumentation%2FAddOns%2Freleased%2FMSSecurity%2FMigrate%3C%2FA%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3EThe%20documentation%20for%20the%20%3CA%20title%3D%22Splunk%20SOAR's%20Windows%20Defender%20ATP%20App%22%20href%3D%22https%3A%2F%2Fsplunkbase.splunk.com%2Fapp%2F5870%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ESplunk%20SOAR%20Windows%20Defender%20ATP%20App%26nbsp%3Bversion%203.5.2%3C%2FA%3E%20is%20here%3A%26nbsp%3B%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fsplunk-soar-connectors%2Fwindowsdefenderatp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2Fsplunk-soar-connectors%2Fwindowsdefenderatp%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3EThe%20Microsoft%20Defender%20for%20Endpoint%20Team%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-3171272%22%20slang%3D%22en-US%22%3E%3CP%3EDownload%20the%20Splunk-supported%20add-on%20for%20Microsoft%20Defender%20for%20Endpoint%20Alerts%20or%20Microsoft%20365%20Defender%20Incidents!%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22SEC20_Security_027.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F349136iC9049B24763901C4%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22SEC20_Security_027.jpg%22%20alt%3D%22SEC20_Security_027.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Co-Authors
Version history
Last update:
‎Feb 17 2022 10:17 AM
Updated by: