<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Splunk on Anything About IT</title><link>https://www.verboon.info/tags/splunk/</link><description>Recent content in Splunk on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 28 Mar 2019 15:17:22 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/splunk/index.xml" rel="self" type="application/rss+xml"/><item><title>How to Configure Splunk to pull Windows Defender ATP alerts</title><link>https://www.verboon.info/2019/03/how-configure-splunk-to-pull-windows-defender-atp-alerts/</link><pubDate>Thu, 28 Mar 2019 15:17:22 +0000</pubDate><guid>https://www.verboon.info/2019/03/how-configure-splunk-to-pull-windows-defender-atp-alerts/</guid><description>&lt;p&gt;Windows Defender ATP provides SIEM integration, allowing you to pull alerts from Windows Defender ATP Security Center into Splunk. The SIEM integration uses the Windows Defender ATP Alerts Rest API. Since I have an actual customer demand for such an integration, I thought it&amp;rsquo;s about time to get a feel for how this works.&lt;/p&gt;
&lt;h1 id="prerequisites"&gt;Prerequisites&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;An active Windows Defender ATP subscription with portal admin access&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Windows Defender ATP SIEM integration enabled within the portal.&lt;/p&gt;</description></item></channel></rss>