MDE_365 _Integration with SIEM(ArcSight)

Akshyalakshmi Anandan Murali 20 Reputation points
2023-06-12T13:42:50.4533333+00:00

Hi All,

In my environment ,we have integrated Microsoft 365 defender (mde) -EDR with ArcSight ,in our case we receive only Alerts and Incidents events only in our ArcSight logs .which is creating more noise and we are not able to create any rule in ArcSight .So wanted to know if we can receive only incidents events from MDE console to ArcSight ?like only incidents events can be integrated with SIEM.

Thanks in Advance

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,217 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
928 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andrew Blumhardt 9,831 Reputation points Microsoft Employee
    2023-06-12T20:49:49.7833333+00:00

    I would think that incidents only would be an option. Can you recount how the ArcSight integration was setup initially? You can stream these alerts and incidents to Sentinel at no additional cost. Once option would be to link M365D to a Sentinel instance (just for this purpose). This could reveal additional options for ArcSight integration with more filtering options. For example, use the workspace data export to send the incidents table to an event hub.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful