Microsoft 365 Defender용 Microsoft Defender for Endpoint REST API 로그 소스 매개변수
Microsoft 365 의 로그 소스를 자동으로 감지하지 못하는 IBM QRadar 경우, Microsoft Defender for Endpoint REST API 프로토콜을 사용하여 QRadar Console 엔드포인트에 Defender 로그 소스를 추가하십시오.
Microsoft Defender for Endpoint REST API 프로토콜을 사용할 때는 반드시 사용해야 하는 특정 매개변수가 있습니다.
중요:
- Microsoft Windows Defender ATP DSM 이름은 이제 Microsoft 365 Defender DSM입니다. DSM RPM 이름은 QRadar에서 Microsoft Windows Defender ATP로 유지됩니다.
- 2021년 11월 25일현재 Microsoft Defender API 스위트의 변경으로 인해 Microsoft는더 이상 SIEM API와의 새 통합 온보딩을 허용하지 않습니다. 자세한 정보는 레거시 SIEM API 사용 중단 (https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/deprecating-the-legacy-siem-api/ba-p/3139643) 을 참조하십시오.
스트리밍 API를 Microsoft Azure 이벤트 허브 프로토콜과 함께 사용하여 QRadar에 이벤트 및 경보 전달을 제공할 수 있습니다. 서비스 및 구성에 대한 자세한 내용은 ' Microsoft 365 Defender 구성: 고급 탐색 이벤트를 Azure Event Hub 으로 스트리밍하기' ( https://docs.micosoft.com/en-us/microsoft-365/security/defender/streaming-api-event-hub?view=o365-worldwide )를 참조하십시오
다음 표는 Microsoft 365 Defender에서 Microsoft Defender for Endpoint REST API 이벤트를 수집하기 위해 특정 값이 필요한 매개변수를 설명합니다:
| 매개변수 | 값 |
|---|---|
| Log Source type | Microsoft 365 Defender |
| Protocol Configuration | Microsoft Defender for Endpoint REST API |
Microsoft Defender for Endpoint REST API 로그 소스 프로토콜 매개변수 및 해당 값의 전체 목록은 Microsoft Defender for Endpoint REST API 프로토콜 구성 옵션을 참조하십시오.