Automating security
Microsoft Defender for Cloud comes with several automation and export capabilities that help you further customize your experience and automatically react to alerts or recommendations.
Continuous export
With continuous export, Defender for Cloud offers a capability to export security alerts, recommendations, secure scores, and regulatory compliance assessment results to a Log Analytics workspace, or to an Azure event hub. By exporting this set of information, you are offered a huge set of capabilities. With data exported to an event hub, you can connect Defender for Cloud to a third-party SIEM solution, such as IBM QRadar, Splunk, SumoLogic, ArcSight, and others. By exporting information to a Log Analytics workspace, you can leverage the data to build your own, custom dashboards based on Power BI, or Azure Monitor Workbooks.
Tip
The Defender for Cloud portal will always provide a just-in-time view of your environment. In case you want access to historical...