Splunk® Supported Add-ons

Splunk Add-on for Microsoft Security

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Use Dashboards to view the analytics for the Splunk Add-on for Microsoft Security

MS Security TA logs Dashboard

You can view the log analytics and performance data for the Splunk Add-on for Microsoft Security using this dashboard.

  1. Navigate to Add-on UI > Log Analytics > MS Security TA logs.
  2. Select time range from timepicker with label Time for logs on the top left corner.
  3. Now you can view different type of analytics and panels related to TA logs.

Panels provided in this Dashboard include:

  • Microsoft Security TA
  • Roles for the MS Security (Requires DEBUG logs enabled)
  • CPU consumption (Supported only on specific OS)
  • Memory consumption (Supported only on specific OS)
  • ATP Alerts ingested
  • Defender Incidents ingested
    • Defender Incidents
    • Defender Alerts associated with Incidents
  • Events from EventHub ingested
  • Advance Hunting ingested
  • Phishing Simulation Attack ingested
  • EPS by MS Security sourcetype (EPS stands for Events per Second)
  • MS Security .conf current changes
  • MS Security .conf update frequency

MS Security TA Errors Dashboard

You can view the Error analytics and performance data sourcetype wise for the Splunk Add-on for Microsoft Security using this dashboard.

  1. Navigate to Add-on UI > Log Analytics > MS Security TA Errors.
  2. Select time range from the time selector with the label Time for logs on the top left corner.
  3. Now you can view different types of analytics and panels related to the TA logs.

Panels provided in this Dashboard:

  • ATP Alerts errors
  • Defender Incidents errors
  • Defender EventHub Input errors
  • Advance Hunting errors
  • Defender Simulations errors
Last modified on 24 April, 2024
PREVIOUS
Configure Alert Actions to collect data for the Splunk Add-on for Microsoft Security
  NEXT
Troubleshoot the Splunk Add-on for Microsoft Security

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters