Skip to main content

hi experts

reaching out to inquire about ingesting Microsoft MDE (Microsoft Defender for Endpoint) data into Chronicle.
Is there any relevant documentation or guides that could assist me

I would start here: https://cloud.google.com/chronicle/docs/administration/feed-management

Defender for Enpoint is incldued in the default parsers: https://cloud.google.com/chronicle/docs/ingestion/ingestion-entities


ok noted , let me have a look


Also suggest .