mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-21 01:37:22 +00:00
Merge remote-tracking branch 'refs/remotes/origin/master' into jdholo
This commit is contained in:
commit
6acff913c9
@ -41,6 +41,9 @@ The _Client credential flow_ uses client credentials to authenticate against the
|
|||||||
|
|
||||||
Use the following method in the Windows Defender ATP API to pull alerts in JSON format.
|
Use the following method in the Windows Defender ATP API to pull alerts in JSON format.
|
||||||
|
|
||||||
|
>[!NOTE]
|
||||||
|
>Windows Defender Security Center merges similar alert detections into a single alert. This API pulls alert detections in its raw form based on the query parameters you set, enabling you to apply your own grouping and filtering.
|
||||||
|
|
||||||
## Before you begin
|
## Before you begin
|
||||||
- Before calling the Windows Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md).
|
- Before calling the Windows Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md).
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user