You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/api/raw-data-export-event-hub.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.topic: reference
15
15
ms.subservice: reference
16
16
ms.custom: api
17
17
search.appverid: met150
18
-
ms.date: 10/24/2023
18
+
ms.date: 06/28/2024
19
19
---
20
20
21
21
# Configure Microsoft Defender for Endpoint to stream Advanced Hunting events to your Azure Event Hubs
@@ -36,14 +36,14 @@ ms.date: 10/24/2023
36
36
37
37
1. Create an [event hub](/azure/event-hubs/) in your tenant.
38
38
39
-
2. Sign in to your [Azure tenant](https://ms.portal.azure.com/), go to **Subscriptions > Your subscription > Resource Providers > Register to Microsoft.insights**.
39
+
2. Sign in to your [Azure tenant](https://ms.portal.azure.com/), go to **Subscriptions** > **Your subscription** > **Resource Providers** > **Register to Microsoft.insights**.
40
40
41
41
> [!IMPORTANT]
42
42
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
43
43
44
44
## Enable raw data streaming
45
45
46
-
1. Sign in to the [Microsoft Defender XDR](https://security.microsoft.com) as a ***Security Administrator***.
46
+
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as a ***Security Administrator***.
47
47
48
48
2. Go to the [Data export settings page](https://security.microsoft.com/securitysettings/defender/raw_data_export) in the Microsoft Defender portal.
49
49
@@ -94,7 +94,7 @@ ms.date: 10/24/2023
94
94
95
95
To get the data types for event properties, do the following:
96
96
97
-
1. Sign in to [Microsoft Defender XDR](https://security.microsoft.com) and go to [Advanced Hunting page](https://security.microsoft.com/hunting-package).
97
+
1. Sign in to [Microsoft Defender portal](https://security.microsoft.com) and go to [Advanced Hunting page](https://security.microsoft.com/hunting-package).
98
98
99
99
2. Run the following query to get the data types mapping for each event:
100
100
@@ -108,13 +108,13 @@ To get the data types for event properties, do the following:
Copy file name to clipboardExpand all lines: defender-endpoint/api/raw-data-export-storage.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -89,7 +89,7 @@ ms.date: 12/18/2020
89
89
90
90
In order to get the data types for our events properties, do the following:
91
91
92
-
1. Sign in to [Microsoft Defender XDR](https://security.microsoft.com) and go to [Advanced Hunting page](https://security.microsoft.com/hunting-package).
92
+
1. Sign in to [Microsoft Defender portal](https://security.microsoft.com) and go to [Advanced Hunting page](https://security.microsoft.com/hunting-package).
93
93
94
94
2. Run the following query to get the data types mapping for each event:
0 commit comments