Configure Microsoft Defender Logs in the Event Hub
Stream Microsoft Defender Events to Azure Event Hubs
You can configure Microsoft Defender Logs into your Azure portal using your Azure Event Hubs Beat.
Verify Your Event Hub
- Log in to your Azure Portal with admin credentials.
- Click All Services, then click Event Hubs.
Verify you have an event hub in the list. If not, you will need to create an event hub.
To create an event hub, see Create Resource Group, Event Hub Namespace and Event Hub.
Verify microsoft.insights is Registered as a Resource Provider
In your Azure Portal under Navigate, click Subscriptions.
Select your subscription, then click Resource providers.
If microsoft.insights does not have the Registered status, click Register.
Microsoft Defender Log Streaming
- Log in to Microsoft Defender portal with Global Admin user credentials.
- In the Microsoft Defender Security Center, click Settings, then click Microsoft 365 Defender.
- Click Streaming API.
- Click Add data export settings.
- Choose a name for your new settings.
- Choose Forward events to Azure Event Hubs
Type in your Event Hubs name and your Event Hubs resource ID.
To obtain your Event Hubs resource ID log in to your Azure Portal. In the Properties tab, you can copy the text under Resource ID.- Choose the events you want to stream and click Save.
References
For more information, see the following Microsoft documentation:
To verify MS Defender detects a threat, you can download the following virus zip file:
- http://www.eicar.org/download/eicar_com.zip
- Upon opening the zip file, you should immediately receive a notification in your system that a virus has been found.