Skip to main content
Question

Is a direct Event Hub feed (without Capture/Blob Storage) supported for Entra ID Audit, MDE and MDI logs?

  • October 6, 2026
  • 2 replies
  • 19 views

0x1k4z

Hi all,

In the Google SecOps feed creation UI, the Microsoft Azure Event Hub source type lets me select log types such as Azure AD Directory Audit, Microsoft Defender for Endpoint and Microsoft Defender for Identity.

However, the documentation for these log types only describes ingestion through Azure Blob Storage (Event Hub Capture for Entra ID Audit, Streaming API to Storage for MDE/MDI).

Is ingesting these log types directly from an Event Hub, without Capture or Blob Storage, officially supported?

Thanks!

2 replies

a_aleinikov
Forum|alt.badge.img+8
  • Bronze 2
  • October 7, 2026

Hi all,

In the Google SecOps feed creation UI, the Microsoft Azure Event Hub source type lets me select log types such as Azure AD Directory Audit, Microsoft Defender for Endpoint and Microsoft Defender for Identity.

However, the documentation for these log types only describes ingestion through Azure Blob Storage (Event Hub Capture for Entra ID Audit, Streaming API to Storage for MDE/MDI).

Is ingesting these log types directly from an Event Hub, without Capture or Blob Storage, officially supported?

Thanks!

Entra ID Audit can be ingested directly from Event Hub.

For MDE and MDI, the documented method is still via Blob Storage, so I wouldn’t treat direct Event Hub ingestion as officially supported unless Google confirms it.

The UI is a bit misleading here.  


dnehoda
Staff
Forum|alt.badge.img+19
  • Staff
  • October 7, 2026

1. Microsoft Defender for Endpoint (MDE)

  • Ingestion Capability: Supported
  • Mechanism: MDE supports a native streaming API. You configure MDE to stream its telemetry directly to your Azure Event Hub From there, Google SecOps continuously pulls the data in near-real-time using the MICROSOFT_DEFENDER_ENDPOINT ingestion label
  • Key Benefit: This setup bypasses API polling limits and ingestion latency, allowing high-throughput endpoint security data (process launches, network connections, registry modifications) to populate your Unified Data Model (UDM) in near-real-time

2. Microsoft Defender for Identity (MDI)

  • Ingestion Capability: Supported
  • Mechanism: MDI alerts and health logs are natively integrated into the broader Microsoft Defender/Microsoft Entra ID ecosystem.

  • Ingestion Route: To pull MDI alerts via Azure Event Hub, you utilize the Microsoft Defender for Cloud Alerts or Microsoft Entra ID Diagnostic Settings stream
    • Active Directory identity protection logs and MDI-generated security alerts are routed to your Event Hub
    • Google SecOps ingests these using the AZURE_AD or AZURE_AD_AUDIT ingestion feeds (diagnostic settings continuous exports) to capture identity and access management security risk detections