cancel
Showing results for 
Search instead for 
Did you mean: 
mmatic
Level 7
Report Inappropriate Content
Message 1 of 3

Azure ATP as a Data Source

I was wondering if anyone had any experience in implementing Azure ATP as a log source for McAfee SIEM. Can anyone provide any work instructions on how to retrieve logs, and if Azure ATP supports forwarding syslog to the event receiver. if so what needs to be done?

Any assistance would be appreciated,

Regards,

Marko

2 Replies
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 2 of 3

Re: Azure ATP as a Data Source

I believe the Office 365 log collector can get this data.

These are recorded in the Graph/Management API as ThreatIntelligence* log types.

At a technical level, the event receiver connects to the Azure APIs at a regular interval to collect this data, so no 'forwarding' is needed. You will just need to configure a new SIEM application inside your Azure tenant.

Brent
Highlighted
McAfee Employee lpinheir
McAfee Employee
Report Inappropriate Content
Message 3 of 3

Re: Azure ATP as a Data Source

In case of forwarding events from Azure thru Syslog settings, you should work with a custom parser.

This should work fine.

References:

Azure ATP Syslog Settings

https://docs.microsoft.com/eu-es/azure-advanced-threat-protection/setting-syslog

Azure ATP security alerts are in CEF format

https://docs.microsoft.com/en-us/azure-advanced-threat-protection/cef-format-sa

This eliminates the need to create a regular expression
for each capture, and will allow the data to be mapped using the CEF key names found
in the log.

For custom parsers please take a look into this documentation:

https://kc.mcafee.com/corporate/index?page=content&id=PD24926&actp=RSS

In addition, I am not sure, but I believe that McAfee is working to create built-in resources to support this a Data Source in a native installation.

brenta's steps can an option as well.

Lucas

 

 

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community