Hi all,
In the Google SecOps feed creation UI, the Microsoft Azure Event Hub source type lets me select log types such as Azure AD Directory Audit, Microsoft Defender for Endpoint and Microsoft Defender for Identity.
However, the documentation for these log types only describes ingestion through Azure Blob Storage (Event Hub Capture for Entra ID Audit, Streaming API to Storage for MDE/MDI).
Is ingesting these log types directly from an Event Hub, without Capture or Blob Storage, officially supported?
Thanks!
Question
Is a direct Event Hub feed (without Capture/Blob Storage) supported for Entra ID Audit, MDE and MDI logs?
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.

