September 2017
Intermediate to advanced
314 pages
8h 5m
English
If your organization has deployed a Security Information and Event Management (SIEM) system, you can pull alerts from the Windows Defender ATP portal using the SIEM connector. Connectors are available for multiple vendors, including Splunk and ArcSight. A generic API is available for others.
Go here for more details: https://docs.microsoft.com/en-us/windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.
Read now
Unlock full access