Microsoft Defender XDR Logs (Beta)

Connecting Microsoft Defender XDR logs to your Panther Console

Overview

Microsoft Defender XDR log ingestion is in open beta starting with Panther version 1.114, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther supports ingesting Microsoft Defender XDR logs via common Data Transport options, like Azure Event Hub and Blob Storage.

How to onboard Microsoft Defender XDR logs to Panther

You'll first create an Azure Blob Storage or Azure Event Hub source in Panther, then configure Azure to export logs to that location.

Prerequisites

Before onboarding Microsoft Defender XDR logs to Panther, ensure that:

Step 1: Create the Microsoft Defender XDR source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Microsoft Defender XDR,” then click its tile.

    • In the slide-out panel, the Transport Mechanism dropdown in the upper-right corner will be pre-populated with the Azure Event Hub option. Either leave this selection as-is, or select Azure Blob Storage.

      An arrow is drawn from a tile in the background titled "Microsoft Defender XDR" to a "Transport Mechanism" dropdown field.
  4. Click Start Setup.

  5. Follow Panther's instructions for configuring an Azure Event Hub or Azure Blob Storage Source.

Step 2: Export Microsoft Defender XDR logs with a streaming API

To export Microsoft Defender XDR logs to Event Hubs or a storage account, follow the instructions below.

For additional support, see the Microsoft Stream Advanced Hunting events to Event Hubs and/or Azure storage account documentation.

  1. In your Azure Portal, navigate to the Microsoft Defender portal at https://security.microsoft.com/.

  2. In the left-hand navigation bar, click Settings. A navigation bar is shown and a "Settings" value is highlighted.

  3. Click Microsoft Defender XDR. Under a "Settings" title, a "Microsoft Defender XDR" option is hovered over.

  4. Under General, click Streaming API. Under a "Microsoft Defender XDR" title, a "Streaming API" value in a navigation bar is clicked.

  5. Under Streaming API, click + Add.

  6. Fill out the form:

    • Name: Enter a descriptive name, e.g., Panther forwarder.

    • Select either Forward events to Azure Storage or Forward events to Event Hub, based the type of log source you created in Panther in Step 1.

      • If you select Forward events to Azure Storage, in the Storage account Resource ID field, enter the ID of your storage account.

      • If you select Forward events to Event Hub, in the Event-Hub Resource ID field, enter the ID of your event hub.

    • Event Types: Select the log categories you'd like to send to Panther. See a full list of event types here. A form titled "Add new Streaming API settings" is shown, with various fields, like Name and Event-Hub Resource ID.

  7. Click Submit.

Supported log types

MicrosoftDefenderXDR.AdvancedHunting

Last updated

Was this helpful?