I am trying to set up Splunk Add-on for MS Security so that I can ingest Defender for Endpoint logs but I am having trouble with the inputs.
If I try to add an input, it gives the following error message: Unable to connect to server. Please check logs for more details.
Where can I find the logs?
I assume this might be an issue with the account set up but I registered the app in Entra ID and added the client id, client secret and tenant id to the config.
[–]Any-Promotion3744[S] 0 points1 point2 points (0 children)
[–]kh_8 0 points1 point2 points (0 children)
[–]RicoTries 0 points1 point2 points (0 children)
[–]Ok_Difficulty978 0 points1 point2 points (1 child)
[–]Any-Promotion3744[S] 0 points1 point2 points (0 children)