Ingest Microsoft Defender XDR insights into Dynatrace

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This playbook will ingest Microsoft Defender XDR insights into Dynatrace.

Attribute Value
Type Playbook
Solution Dynatrace
Source View on GitHub

Additional Documentation

📄 Source: Ingest-DynatraceMSDefenderXDR/readme.md

Ingest-DynatraceMSDefenderXDR

author: Dynatrace

This playbook will ingest Microsoft Defender XDR insights to Dynatrace. You need a valid Dynatrace tenant with Application Security enabled, you will also need to install the Microsoft Defender XDR Sentinel connector to make use of this playbook. To learn more about the Dynatrace platform Start your free trial

** Prerequisites ** - Follow these instructions to generate a Dynatrace access token, the token should have Ingest logs (logs.ingest) scope. - [Important step]Store the Dynatrace Access Token as a secret in Azure Key vault and provide the key vault name during playbook deployment, by convention the secret name should be 'DynatraceAccessToken'.

** Post Install Notes:**

The Logic App uses a Managed System Identity (MSI).

Assign RBAC 'Microsoft Sentinel Reader' role to the Logic App at the Resource Group level of the Log Analytics Workspace.

Assign access policy on key vault for Playbook to fetch the secret key

Initial Setup

A Microsoft Sentinel playbook is utilized by automation rules, therefore to automatically trigger this playbook you must setup a new automation rule. If you have not set permissions yet, review here

Basic steps for setup of the playbook and automation rule are as follows :

  1. Go to the Automation blade in Microsoft Sentinel.
  2. Create a new playbook from the 'Ingest Microsoft Defender XDR insights into Dynatrace' playbook template - KeyvaultName: The name of the keyvault created as pre-requisite - DynatraceTenant: xyz.dynatrace.com
  3. Create a new automation rule - Name : Ingest Microsoft Defender XDR insights into Dynatrace - Trigger : When alert is created - Conditions : If Analytic rule name contains 'Dynatrace Application Security - Attack detection' - Actions : Run playbook IngestDynatraceMSDefender365

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to Dynatrace