Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security operations center (SOC) needs to integrate Microsoft Defender for Endpoint with their existing Security Information and Event Management (SIEM) system. They want to stream all Defender for Endpoint alerts and raw event data to the SIEM for centralized logging, correlation, and long-term retention. Which method should the SOC implement to achieve this real-time data export?

  1. AUse Microsoft Defender XDR's streaming API to Azure Event Hubs.
  2. BEnable email notifications for all Defender for Endpoint alerts.
  3. CManually export alerts from the Microsoft 365 Defender portal.
  4. DConfigure API-based integration using the Defender for Endpoint APIs.
Show answer & explanation

Correct answer: A. Use Microsoft Defender XDR's streaming API to Azure Event Hubs.

The most scalable and efficient way to stream all Defender for Endpoint alerts and raw event data to an external SIEM system, especially for real-time processing and long-term retention, is to use Microsoft Defender XDR's streaming API to Azure Event Hubs. From Event Hubs, data can then be ingested by various SIEM solutions.

Why the other options are wrong

  • B. Email notifications are for immediate awareness, not for streaming raw event data or for SIEM ingestion.
  • C. Manual export is not scalable or real-time for continuous data streaming.
  • D. While APIs can be used, the streaming API to Azure Event Hubs is specifically designed for high-volume, real-time data export of all alerts and raw events, making it more efficient than building custom API integrations for this scale.

MDE SIEM Integration

Microsoft Defender for Endpoint integrates with SIEM systems to centralize security data for analysis and correlation.

  • Streaming API to Azure Event Hubs is the primary method for real-time data export.
  • Exports alerts and raw event data.
  • Enables centralized logging and long-term retention.

Memory trick: To send all MDE data, you need a 'Hub' to stream it through, not just a manual copy or email.

More Mitigate threats using Microsoft Defender XDR questions