hi experts
reaching out to inquire about ingesting Microsoft MDE (Microsoft Defender for Endpoint) data into Chronicle.
Is there any relevant documentation or guides that could assist me
I would start here:
https://cloud.google.com/chronicle/docs/administration/feed-management
Defender for Enpoint is incldued in the default parsers:
https://cloud.google.com/chronicle/docs/ingestion/ingestion-entities
ok noted , let me have a look
Also suggest .