mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 05:17:22 +00:00
3.7 KiB
3.7 KiB
title, description, keywords, search.product, search.appverid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, ms.author, author, ms.localizationpriority, manager, audience, ms.collection, ms.topic
title | description | keywords | search.product | search.appverid | ms.prod | ms.mktglfcycl | ms.sitesec | ms.pagetype | ms.author | author | ms.localizationpriority | manager | audience | ms.collection | ms.topic |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Stream Microsoft Defender Advanced Threat Protection events. | Learn how to configure Microsoft Defender ATP to stream Advanced Hunting events to your Event Hub. | raw data export, streaming API, API, Azure Event Hubs, Azure storage, storage account, Advanced Hunting, raw data sharing | eADQiWindows 10XVcnh | met150 | w10 | deploy | library | security | macapara | mjcaparas | medium | dansimp | ITPro | M365-security-compliance | article |
Configure Microsoft Defender ATP to stream Advanced Hunting events to your Azure Event Hubs
Applies to:
Want to experience Microsoft Defender ATP? Sign up for a free trial.
Before you begin:
- Create an event hub in your tenant.
- Log in to your Azure tenant, go to Subscriptions > Your subscription > Resource Providers > Register to Microsoft.insights.
Enable raw data streaming:
- Log in to Microsoft Defender Security Center with a Global Admin user.
- Go to Data export settings page on Microsoft Defender Security Center.
- Click on Add data export settings.
- Choose a name for your new settings.
- Choose Forward events to Azure Event Hubs.
- Type your Event Hubs name and your Event Hubs resource ID. In order to get your Event Hubs resource ID, go to your Azure Event Hubs namespace page on Azure > properties tab > copy the text under Resource ID:
- Choose the events you want to stream and click Save.
The schema of the events in Azure Event Hubs:
{
"records": [
{
"time": "<The time WDATP received the event>"
"tenantId": "<The Id of the tenant that the event belongs to>"
"category": "<The Advanced Hunting table name with 'AdvancedHunting-' prefix>"
"properties": { <WDATP Advanced Hunting event as Json> }
}
...
]
}
- Each event hub message in Azure Event Hubs contains list of records.
- Each record contains the event name, the time Microsoft Defender ATP received the event, the tenant it belongs (you will only get events from your tenant), and the event in JSON format in a property called "properties".
- For more information about the schema of Microsoft Defender ATP events, see Advanced Hunting overview.
Data types mapping:
To get the data types for event properties do the following:
- Log in to Microsoft Defender Security Center and go to Advanced Hunting page.
- Run the following query to get the data types mapping for each event:
{EventType}
| getschema
| project ColumnName, ColumnType
- Here is an example for Machine Info event: