The Microsoft Windows Defender Status Check Add-on for Splunk allows users to check their Defender ATP configuration status for Windows machines. It uses the Windows Registry to find the configuration status for Defender ATP. The Add-on does not contain any dashboards or savedsearches.
Install the Cyences App for Splunk (https://splunkbase.splunk.com/app/5351/) to easily audit the configuration status check for Office 365 Defender ATP on endpoints by using the Microsoft 365 Defender ATP Audit dashboard.
Fixed event format issue.
Events are now being ingested directly via Powershell script, with no file monitoring being used anymore.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.