Skip to main content


hi experts





reaching out to inquire about ingesting Microsoft MDE (Microsoft Defender for Endpoint) data into Chronicle.


Is there any relevant documentation or guides that could assist me


I would start here:
https://cloud.google.com/chronicle/docs/administration/feed-management






Defender for Enpoint is incldued in the default parsers:
https://cloud.google.com/chronicle/docs/ingestion/ingestion-entities



ok noted , let me have a look



Also suggest
.


Reply