IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Parsing logs from Microsoft defender for cloud

    Posted Mon October 24, 2022 07:18 AM
    Hello all,

    does anyone have some tips/tricks/guides for parsing the Microsoft defender for cloud logs in Qradar? Info such what is important to parse, what not etc.
    Thank you.

    Regards

    ------------------------------
    Tomas Tyser
    ------------------------------


  • 2.  RE: Parsing logs from Microsoft defender for cloud

    Posted Tue October 25, 2022 07:44 AM
    Hi,

    For defender cloud I use "QRadar Microsoft 365 Defender DSM and depending on the event type, I make some custom properties. For example:

    Event Name: Process Created
    category
    DeviceName
    FileName
    FolderPath
    ProcessCommandLine
    Hash

    Event Name : Interactive Logon Success
    LogonType
    Protocol
    AccountDisplayName
    AccountUpn
    AccountName
    AccountDomain
    TargetComputerOperatingSystem

    And so on...

    https://www.ibm.com/docs/en/dsm?topic=microsoft-365-defender

    ------------------------------
    Carlos Medina
    ------------------------------



  • 3.  RE: Parsing logs from Microsoft defender for cloud

    Posted Wed October 26, 2022 09:13 AM
    Hello Carlos, thank you for the reply. I did try that first, but I could not find the type of events under M 365 D I get from the Cloud :/

    ------------------------------
    Tomas Tyser
    ------------------------------



  • 4.  RE: Parsing logs from Microsoft defender for cloud

    Posted Wed October 26, 2022 09:27 AM

    Hi Tomas,

    I would recommend to use content pack which parses fields from payload:

    take a look:

    https://exchange.xforce.ibmcloud.com/hub/extension/c8e594fa5d744dcb23859a8fb060bc9d



    ------------------------------
    [Ashish] [Khandewale] [Security Consultant]
    [SIOC]
    [IBM Canada]
    ------------------------------