# Integrate Microsoft Defender with Elastic

**URL:** <https://discuss.elastic.co/t/integrate-microsoft-defender-with-elastic/356079>\
**Category:** Elastic Security\
**Created:** [March 25, 2024, 7:37am UTC](https://discuss.elastic.co/t/integrate-microsoft-defender-with-elastic/356079 "2024-03-25T07:37:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajith\_pathiraja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajith_pathiraja/32/116741_2.png) [@rajith\_pathiraja](https://discuss.elastic.co/u/rajith_pathiraja)\
**Post date:** [March 25, 2024, 7:37am UTC](https://discuss.elastic.co/t/integrate-microsoft-defender-with-elastic/356079/1 "2024-03-25T07:37:54Z")

</div>

I have tried to integrate MS Defender with Elastic and unable to get the logs to elastic. I have followed the standard guideline given in Elastic documentation. Any one face the same issue ?

---

<div class="post-metadata">

**Author:** ![Maxim\_Palenov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxim_palenov/32/122504_2.png) [@Maxim\_Palenov](https://discuss.elastic.co/u/Maxim_Palenov)\
**Post date:** [March 25, 2024, 5:12pm UTC](https://discuss.elastic.co/t/integrate-microsoft-defender-with-elastic/356079/2 "2024-03-25T17:12:10Z")

</div>

Hi @rajith_pathiraja,

Could you describe the steps you've performed to set up to integrate MS Defender with Elastic? It's also important to know your set up. Do you have Elastic Security deployed in Elastic cloud or on-premises? What Kibana version do you use? What integration and what version you've installed? Have you created an agent policy with MS Defender integration configuration? Are you sure that policy has been picked up by agents?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [March 27, 2024, 12:44pm UTC](https://discuss.elastic.co/t/integrate-microsoft-defender-with-elastic/356079/3 "2024-03-27T12:44:01Z")

</div>

Hi @rajith_pathiraja

Are any error messages returned? In Kibana \> Discover, if you are using the integration with Elastic Agent, select the logs-\* data stream and in the search bar, type event.module: "namemodule". Press the W key to list the modules and see if any error messages appear. As an example, I am collecting logs from the Office 365 integration, in the search bar, it would be event.module: "o365".

 ![print01](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b1bb5b8b5682572cdf2b6fd936c49ad85c0bdd9f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2024, 12:44pm UTC](https://discuss.elastic.co/t/integrate-microsoft-defender-with-elastic/356079/4 "2024-04-24T12:44:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
