May 17 2019 10:20 AM
Does Azure ATP allow you to send events to Events Hub (https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-about)?
I'm not very familiar with Events Hub, but know we are collecting events from there, so if we start sending Azure ATP data there, we can just scoop it right up with minimal change in processes.
May 20 2019 02:30 PM
May 21 2019 02:18 PM
Hi
No you can send events to event hub then to Azure ATP. AATP collects its data from the sensor. You have to install the sensor on your domain controllers in Active Directory.
May 22 2019 05:57 AM
I understand we need the sensors to get the data into AATP, I was referring to Suspicious Activity and Health alerts being sent to Events Hub, rather than using a sensor to syslog the events to our SIEM. Just seems like a little cleaner solution for our environment, if available.
May 22 2019 05:59 AM
SolutionFor alerts outbound, today we support the syslog model only. We have a public preview coming soon that will move AATP to a new portal. When moving to that portal, the event hubs model will work.
Dec 10 2019 05:02 AM
@Nicholas DiCola (SECURITY JEDI) Hello, I'm also looking at configuration options to forward ATP alerts to EventHub. Is the "ATP to a new portal." online now? If there are any documentation links you can provide that would be great.
Thanks!
Dec 10 2019 07:57 AM
there is no way to send Azure ATP alerts to event hubs.
Dec 10 2019 09:46 AM
@Nicholas DiCola (SECURITY JEDI) Thanks for the reply.
I thought I read there is a way to get ATP events to Eventhub, maybe via Azure Sentinel?