Configuring the Application

Adding a Normalization Policy

  1. Click Configure from the left navigation bar.

  2. Under Entities, click Normalization Policies.

  3. Select LogPoint machines to create a normalization policy. You can select multiple machines of different pools.

  4. Click Next.

_images/microsoft_dcui_configure_normpolicy_select_lp.png

Selecting LogPoint Machines

  1. Enter a Name.

  2. Select MicrosoftDefenderATPCompiledNormalizer from the list of compiled normalizers, and click Add to List.

  3. Click Next.

_images/microsoft_dcui_configure_normpolicy.png

Adding a Normalization Policy

  1. Review your changes. You can go Back to make any changes if necessary.

Note

Click Download Report to save the summary of the task in PDF.

  1. Click Finish and click OK to confirm.

_images/microsoft_dcui_configure_normpolicy_confirm.png

Confirming the Changes

Configuring the Microsoft Defender ATP Fetcher

  1. Click Configure from the left navigation bar.

  2. Under Settings, click Plugins.

  3. Select Microsoft Defender ATP Fetcher from the Select Plugin Type drop-down.

  4. Select LogPoint machines to configure the Microsoft Defender ATP Fetcher. You can select multiple machines of different pools where the Microsoft Defender ATP application is installed.

  5. Click Next.

_images/microsoft_dcui_configure_selecting_lp.png

Selecting LogPoint Machines

  1. Select Create.

  2. Enter the Client ID, which is the application ID provided by the Azure Active Directory to the registered clients.

  3. Enter the Client Secret, which is a secret password created for the application.

  4. Enter the Azure Active Directory Authorization server URL.

  5. Enter the Events URL. The application fetches logs of the specified event.

  6. Select the Fetch Interval in minutes.

  7. Select a Processing Policy that uses the previously created normalization policy.

  8. Select the Charset.

_images/microsoft_dcui_configure.png

Configuring the Microsoft Defender ATP Fetcher

  1. Select Enable Proxy if you use a proxy server.

  2. In the Proxy Configuration section:

    15.1 Enter the IP address and the Port number of the proxy server.

    15.2 Select HTTP or HTTPS protocol as required.

  3. Click Next.

_images/microsoft_dcui_configure_enable.png

Enabling Proxy

  1. Review your changes. You can go Back to make any changes if necessary.

Note

Click Download Report to save the summary of the task in PDF.

  1. Click Finish and click OK to confirm.

_images/microsoft_dcui_edit_confirm12.png

Confirming the Changes

Editing a Microsoft Defender ATP Fetcher Configuration

  1. Click Configure from the left navigation bar.

  2. Under Settings, click Plugins.

  3. Select Microsoft Defender ATP Fetcher from the Select Plugin Type drop-down.

  4. Select LogPoint machines to configure the Microsoft Defender ATP Fetcher. You can select multiple machines of different pools where the Microsoft Defender ATP application is installed.

  5. Click Next.

_images/microsoft_dcui_configure_selecting_lp.png

Selecting LogPoint Machines

  1. Select List.

Note

The page lists only the configurations that are common to all the selected LogPoint machines.

  1. Click the Edit icon for the configuration from the Action column.

_images/microsoft_dcui_edit_list.png

Listing the Microsoft Defender ATP Fetcher Configuration

  1. Make the necessary changes and click Edit.

_images/microsoft_dcui_edit.png

Editing a Microsoft Defender ATP Fetcher Configuration

The Action Status of the configuration changes to Changed. You can click the Undo icon from the Action column to undo the changes.

  1. Click Next.

_images/microsoft_dcui_edit_review.png

Verifying the Action Status

  1. Review your changes. You can go Back to make any changes if necessary.

Note

Click Download Report to save the summary of the task in PDF.

  1. Click Finish and click OK to confirm.

_images/microsoft_dcui_edit_confirm.png

Confirming the Changes

Deleting a Microsoft Defender ATP Fetcher Configuration

  1. Click Configure from the left navigation bar.

  2. Under Settings, click Plugins.

  3. Select Microsoft Defender ATP Fetcher from the Select Plugin Type drop-down.

  4. Select LogPoint machines to configure the Microsoft Defender ATP Fetcher. You can select multiple machines of different pools where the Microsoft Defender ATP application is installed.

  5. Click Next.

_images/microsoft_dcui_configure_selecting_lp.png

Selecting LogPoint Machines

  1. Select List.

Note

The page lists only the configurations that are common to all the selected LogPoint machines.

  1. Click the Delete icon for the configuration from the Action column.

_images/microsoft_dcui_delete_list.png

Listing the Microsoft Defender ATP Fetcher Configurations

The Action Status of the configuration changes to Delete. You can click the Undo icon from the Action column to undo the deletion.

  1. Click Next.

_images/microsoft_dcui_delete_review.png

Verifying the Action Status

  1. Review your changes. You can go Back to make any changes if necessary.

Note

Click Download Report to save the summary of the task in PDF.

  1. Click Finish and click OK to confirm.

_images/microsoft_dcui_delete_confirm.png

Confirming the Changes


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support