Skip to content

Commit 08ff53e

Browse files
author
David Curwin
committed
Export alerts update
1 parent 236a6de commit 08ff53e

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

articles/defender-for-cloud/export-to-siem.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -140,7 +140,7 @@ To view the event schemas of the exported data types, visit the [Event Hubs even
140140

141141
## Use the Microsoft Graph Security API to stream alerts to third-party applications
142142

143-
As an alternative to Microsoft Sentinel and Azure Monitor, you can use Defender for Cloud's built-in integration with [Microsoft Graph Security API](https://www.microsoft.com/security/business/graph-security-api). No configuration is required.
143+
As an alternative to Microsoft Sentinel and Azure Monitor, you can use Defender for Cloud's built-in integration with [Microsoft Graph Security API](/graph/security-concept-overview/). No configuration is required.
144144

145145
You can use this API to stream alerts from your **entire tenant** (and data from many Microsoft Security products) into third-party SIEMs and other popular platforms:
146146

@@ -150,6 +150,9 @@ You can use this API to stream alerts from your **entire tenant** (and data from
150150
- **QRadar** - [Use IBM's Device Support Module for Microsoft Defender for Cloud via Microsoft Graph API](https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/c_dsm_guide_ms_azure_security_center_overview.html).
151151
- **Palo Alto Networks**, **Anomali**, **Lookout**, **InSpark**, and more - [Use the Microsoft Graph Security API](https://www.microsoft.com/security/business/graph-security-api#office-MultiFeatureCarousel-09jr2ji).
152152

153+
> [!NOTE]
154+
> The preferred way to export alerts is through [Continuously export Microsoft Defender for Cloud data](continuous-export.md).
155+
153156
## Next steps
154157

155158
This page explained how to ensure your Microsoft Defender for Cloud alert data is available in your SIEM, SOAR, or ITSM tool of choice. For related material, see:

0 commit comments

Comments
 (0)