Procedure
- Enable Microsoft Defender for Endpoint Log Collection for a new or existing Azure
subscription:
- Go to .
- Click the Azure tab.
- Click Add Subscription or select an Azure subscription from the list.
- On the Features and permissions page (if you are adding a new subscription), or the Resource update tab (if you are configuring an existing subscription), enable Microsoft Defender for Endpoint Log Collection .
- By default Microsoft Defender for Endpoint Log Collection deploys to all regions. To remove regions, click the Deployment list and clear the checkbox beside each region you want to remove.
- Specify which log repository in which to save log data:
- Click Scanner settings.
- Select a log repository from the list. If no log repositories exist, click the link to add a log repository in Data Source and Log Management. After adding a log repository, click the refresh icon to show the repository in the list and select it.
- Save your changes. If you are adding a new Azure subscription, complete the steps to add the subscription. For more information, see Adding an Azure subscription.
- Configure Microsoft Defender to export events:
- In Microsoft Defender, go to General > Streaming API.
- Click Add to create a new Streaming API setting.
- Provide a name for the setting.
- Select Forward events to Event Hub.
- In the Event-Hub Resource ID field, enter
/subscriptions/{subscriptionID}/resourceGroups/trendmicro-clm-mde-rg/providers/Microsoft.EventHub/namespaces/clm-eventhub-ns-{first 8 chars of subscriptionID}
. - In the Event-Hub name field, enter
insights-logs-advancedhunting
. - In the Event Types area, select all Alerts & Behaviors and Devices.
- Click Submit.