Default Version 0.4.3
August 7, 2023
August 7, 2023
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 5.x, 4.x
Log in to rate this app
#47 in Endpoint
This extension for Splunk® is a rewrite of the Add-on already created by pdoconnell (TA-microsoft-windefender) that we adapt to our needs and requirements. This add-on is intended as a complement to the Splunk Add-on for Microsoft Windows, which also manages the basic operations of the field extraction from the xml or raw events. If you have installed that add-on you can also use this one to extract more information and present it according to CIM. Code is hosted on Github: https://github.com/nextpart/Defender_TA_nxtp
Log in to report this app listing.