# Can filebeat's o365 module fetch windows defender logs

**URL:** https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575
**Category:** Beats
**Tags:** filebeat
**Created:** [October 27, 2022, 2:25am UTC](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575 "2022-10-27T02:25:04Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![sriramb12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sriramb12/32/110719_2.png) [@sriramb12](https://discuss.elastic.co/u/sriramb12)
#### Post date: [October 27, 2022, 2:25am UTC](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575/1 "2022-10-27T02:25:04Z")

</div>

Hello Team  
I am looking for some insights on fetching windwos defender logs via filebeat (o365 module)  
Currently the o365 config (yml) lists these:

# List of content-types to fetch. By default all known content-types

```
# are retrieved:
var.content_type:
  - "Audit.AzureActiveDirectory"
  - "Audit.Exchange"
  - "Audit.SharePoint"
  - "Audit.General"
  - "DLP.All"

```

How can we get windows defender logs (is this going to be a new category? etc) ?

---

<div class="post-metadata">

### Author: ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)
#### Post date: [November 4, 2022, 4:20pm UTC](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575/2 "2022-11-04T16:20:13Z")

</div>

Hi @sriramb12,

To ingest Defender events, I'd recommend our [Defender for Endpoint](https://docs.elastic.co/integrations/microsoft_defender_endpoint) integration. It requires Elastic Agent, so you'll need to spin up an Agent to ingest the events. We also have an M365 Defender integration if that's of interest too.

---

<div class="post-metadata">

### Author: ![sriramb12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sriramb12/32/110719_2.png) [@sriramb12](https://discuss.elastic.co/u/sriramb12)
#### Post date: [November 10, 2022, 8:35pm UTC](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575/3 "2022-11-10T20:35:50Z")

</div>

Hello Jamie  
thanks so much! It helped to an extent, that I can ask next question. Currently I am using 0365.yml (within modules.d) to fetch Azure AD logs. I have set up the windows defender app within Azure tenant (portal) . So is there a different filebeat module I need to add this applicationID /secret details?  
Currently the Azure AD logs are fetched using filebeat and the config looks like this:

```auto
/etc/filebeat/modules.d/o365.yml
sudo cat o365.yml | grep -v "#"

- module: o365
  audit:
    enabled: true

    var.application_id: "xxxx-xx-xx-8xxx-xxxxxxx"

    var.tenants:
     - id: "xx-xx-xx-xx-xxxxx"
       name: "xxxxx.onmicrosoft.com"
    var.client_secret: "IXv8Q~xxxxxx.ZMbSD"
                        

    var.content_type:
      - "Audit.AzureActiveDirectory"
      - "Audit.Exchange"
      - "Audit.SharePoint"
      - "Audit.General"
      - "DLP.All"

```

The question is, do I need to run another module for dealing with windoes defender logs?  
If so, do I need to upgrade the filebeat (currently running 8.2.3) ? etc

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 8, 2022, 10:36pm UTC](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575/4 "2022-12-08T22:36:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
