A security team is using Microsoft Defender XDR and wants to integrate security alerts and incidents with their existing Security Information and Event Management (SIEM) system. They require near real-time streaming of all high-severity alerts. Which capability within Microsoft Defender XDR should the administrator configure?
- AEmail notifications for alerts.
- BMicrosoft Defender XDR Streaming API.
- CManual export of alert data.
- DMicrosoft Purview eDiscovery.
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Defender XDR Streaming API.
The Microsoft Defender XDR Streaming API is designed to provide a near real-time feed of alerts and incidents from across the Defender XDR suite to external systems like SIEMs, data lakes, or custom applications. This allows for automated ingestion and correlation of security data. Email notifications are for human awareness, manual export is not real-time, and eDiscovery is for compliance/legal holds.
Why the other options are wrong
- A. Email notifications are for human consumption and do not provide a structured, automated feed for a SIEM system.
- C. Manual export is not near real-time and is impractical for continuous integration with a SIEM.
- D. Microsoft Purview eDiscovery is used for legal hold and content search for compliance, not for streaming security alerts to a SIEM.
Defender XDR Streaming API
The Microsoft Defender XDR Streaming API provides a near real-time feed of security alerts, incidents, and raw event data from across Microsoft Defender XDR services to external systems like SIEMs or data lakes.
- Uses Azure Event Hubs and/or Storage Accounts.
- Enables automated integration with SIEM/SOAR.
- Provides a continuous stream of security data.
- Configurable for specific data types (alerts, events).
Memory trick: Remember, to 'Stream' 'Defender XDR' 'Alerts' to your 'SIEM', use the 'Streaming API'.