You can enable Microsoft Defender for Endpoint Log Collection on both new and existing
Azure subscriptions in Cloud Accounts. Trend Vision One collects the data from Microsoft Defender and saves it in a log repository that you
specify, which you then can view in Data Source and Log Management. After enabling the feature in Trend Vision One you must configure Microsoft Defender to export events to Trend Vision One.
Procedure
- Enable Microsoft Defender for Endpoint Log Collection for a new or existingAzure subscription:
- Go to .
- Click the Azure tab.
- Click Add Subscription or select an Azure subscription from the list.
- On the Features and permissions page (if you are adding a new subscription), or the Resource update tab (if you are configuring an existing subscription), enable Microsoft Defender for Endpoint Log Collection .
- By default Microsoft Defender for Endpoint Log Collection deploys to all regions. To remove regions, click the Deployment list and clear the checkbox beside each region you want to remove.
- Specify which log repository in which to save log data:
- Click Scanner settings.
- Select a log repository from the list. If no log repisories exist, click the link to add a log repository in Data Source and Log Management. After adding a log repository, click the refresh icon to show the repository in the list and select it.
- Save your changes. If you are adding a new Azure subscription, complete the steps to add the subscription. For more information, see Adding an Azure subscription.
- Configure Microsoft Defender to export events:
- In Microsoft Defender, go to General > Streaming API.
- Click Add to create a new Streaming API setting.
- Provide a name for the setting.
- Select Forward events to Event Hub.
- In the Event-Hub Resource ID field, enter
/subscriptions/{subscriptionID}/resourceGroups/trendmicro-clm-mde-rg/providers/Microsoft.EventHub/namespaces/clm-eventhub-ns-{first 8 chars of subscriptionID}
. - In the Event-Hub name field, enter
insights-logs-advancedhunting
. - In the Event Types area, select all Alerts & Behaviors and Devices.
- Click Submit.