is it possible to collect windows log with windows defender for endpoint

TomVanDerPo 0 Reputation points
2025-01-14T14:12:32.89+00:00

Hello,

We plan to install windows defender for endpoint at all computer workstations. The question is whether it is possible to collect Windows log (not only antivirus, but also system, applications, DLP) with windows defender for endpoint

Thanks for an answer

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,469 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 34,891 Reputation points Microsoft Employee
    2025-01-16T08:12:10.3633333+00:00

    @TomVanDerPo Thank you for reaching out to us.

    Microsoft Defender for Endpoint is primarily an endpoint protection platform that provides antivirus, endpoint detection and response (EDR), and other security features. While it can collect some system and application logs, it is not designed to be a comprehensive log collection tool.

    If you need to collect logs from your workstations, you may want to consider using Microsoft Sentinel, which is a cloud-native security information and event management (SIEM) solution that can collect and analyze logs from a variety of sources, including Windows Event Logs, Sysmon, and other security solutions.

    Alternatively, you can use the Azure Monitoring Agent to collect logs from your workstations and send them to a Log Analytics workspace, which can then be used for analysis and alerting. However, this approach requires additional configuration and management compared to using Sentinel.

    Reference: https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-overview

    https://www.youtube.com/watch?v=uPjCE1KZqR4

    https://www.youtube.com/watch?v=Z1zDlXCwI9k&t=465s

    Let me know if you have any further questions, feel free to post back.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.