Nov 02 2022 11:33 PM
Hello,
I have a question, if i need to ingest the logs of an endpoint device without onboard the machine to Defender, i have 2 options, Log Analytics Agent & MMA agent, but it's not get the logs in the form as Defender get, like the following tables (DeviceEvents, DeviceProccess,,,etc),
how i can get these tables logs without onboarding the device to Defender??
Thanks.
Nov 03 2022 04:43 AM
SolutionNov 03 2022 04:43 AM
Solution