Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security operations center (SOC) needs to ensure that all security events from Microsoft Defender for Endpoint are ingested into their existing third-party Security Information and Event Management (SIEM) system for centralized logging and correlation. They want to avoid using Azure Event Hubs as an intermediary due to existing architectural constraints. Which direct integration method should the SOC team prioritize for connecting Defender for Endpoint to their SIEM?

  1. AMicrosoft Graph Security API
  2. BSyslog forwarding
  3. CPowerShell cmdlets
  4. DStreaming API
Show answer & explanation

Correct answer: D. Streaming API

The Streaming API (part of the Data Streaming API in Defender XDR) is the recommended method for pushing raw security events and alerts directly from Microsoft Defender for Endpoint to external systems, including SIEMs, without requiring Azure Event Hubs as an intermediary.

Why the other options are wrong

  • A. The Microsoft Graph Security API is primarily for pulling alerts and security data on demand, not for continuous streaming of raw events.
  • B. Syslog forwarding is not a native, direct integration method for raw Defender for Endpoint events; it's typically used for device-level logs or specific appliances.
  • C. PowerShell cmdlets are for management and automation, not for continuous, real-time data streaming to a SIEM.

MDE Streaming API (SIEM Integration)

A Microsoft Defender for Endpoint API that enables continuous, real-time streaming of raw security events and alerts directly to external Security Information and Event Management (SIEM) systems or other data repositories.

  • Provides raw event data.
  • Supports direct integration with SIEMs.
  • Does not require Azure Event Hubs as an intermediary.

Memory trick: To 'stream' data directly, use the 'Streaming API', not pull or old protocols.

More Mitigate threats using Microsoft Defender XDR questions