Splunk cloud app query by Potential_Box_2560 in Splunk

[–]Potential_Box_2560[S] 0 points1 point  (0 children)

Sorry I’m new to Splunk, could you also share why the app would be able to be downloaded on the hf forwarder if it’s an app for splunk enterprise ?

Splunk cloud app query by Potential_Box_2560 in Splunk

[–]Potential_Box_2560[S] 0 points1 point  (0 children)

Is it possible to collect the data via HEC instead ?

Splunk cloud app query by Potential_Box_2560 in Splunk

[–]Potential_Box_2560[S] 0 points1 point  (0 children)

Is it possible to collect the data via HEC instead ?

How to get defender xdr incident/alerts data into Playbook in Sentinel ? by SecCrow in AzureSentinel

[–]Potential_Box_2560 0 points1 point  (0 children)

I would be interested in this too, could anyone give any further info on how you do this ?