Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Defender for Office connector creates streaming API without AlertInfo

Open hazcod opened this issue 3 years ago • 6 comments

Describe the bug

Using the native (codeless) Defender for Office in Sentinel creates a Defender for Office streaming API without AlertInfo. I believe this will make us miss important alerts.

image

To Reproduce

  1. Enable Defender for Office Dataconnector in Sentinel.
  2. Got to https://security.microsoft.com/settings/mtp_settings/raw_data_export
  3. Notice AlertInfo not being enabled.

Expected behavior AlertInfo enabled.

hazcod avatar Nov 14 '22 09:11 hazcod

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Nov 14 '22 09:11 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Nov 16 '22 09:11 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 15 '22 09:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Apr 10 '23 13:04 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Apr 10 '23 13:04 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Apr 12 '23 04:04 github-actions[bot]

Hi @hazcod are you still facing this issue, please confirm, thanks!

v-vdixit avatar May 05 '23 05:05 v-vdixit

Yes, nothing changed about the connector.

hazcod avatar May 05 '23 08:05 hazcod

Hi @hazcod thanks for your patience and understanding, we are discussing with the author of the connector regarding this issue, will update you shortly.

v-vdixit avatar Jun 08 '23 10:06 v-vdixit

Hi @hazcod we are working with the concerned team, will update you once we hear back from them, thanks!

v-vdixit avatar Jun 15 '23 06:06 v-vdixit

Hi @hazcod we are still waiting to hear back from the team, thanks!

v-vdixit avatar Jun 21 '23 13:06 v-vdixit

Hi @hazcod to use the Defender for Office streaming API with AlertInfo, please ensure that you have followed all steps mentioned in the documentation and that all pre requisites are met, please check the documentation here - Microsoft Defender for Office 365 connector for Microsoft Sentinel, thanks!

v-vdixit avatar Jun 23 '23 12:06 v-vdixit

Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond on it in the next 2 days. If we don't receive response, we will be closing this issue as per our standard procedures, thanks!

v-vdixit avatar Jun 30 '23 08:06 v-vdixit

Since we have not received a response in the last 5 days, we are closing your issue as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation

v-vdixit avatar Jul 03 '23 05:07 v-vdixit

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jul 03 '23 05:07 github-actions[bot]

If anyone else runs into this, make sure that under the Defender XDR data connector in Sentinel, "AlertInfo" is selected under "Microsoft Defender Alerts".

DevSecNinja avatar Jan 02 '24 12:01 DevSecNinja