Skip to main content

CollectorsCloud Collectors Administration Guide

Migrate the Microsoft Defender XDR (via Event Hub) Cloud Collector

The Microsoft Defender XDR (via Event Hub) Cloud Collector enables you to ingest logs into the Exabeam Security Operations Platform and use the Search service to find specific events in those logs.

If you previously used the Office 365 Cloud Connector that was part of the SaaS Cloud Connectors, migration to the Cloud Collectors service is recommended. Before you migrate, consider the following:

  • License Requirements: No additional license is required. The Cloud Collectors app is included with your existing license.

  • SaaS Cloud Connectors Support: Both the SaaS Cloud Connectors and the new Cloud Collectors environments can run in parallel.

The following table displays the endpoints of the Office 365 SaaS Cloud Connector that are now mapped to the new Microsoft Defender XDR (via Event Hub) Cloud Collector.

Legacy Endpoint

Configuration for Microsoft Defender XDR

mcas-alert

CloudApp events

mcas-activities

CloudApp events

The cloud collector supports XDR capabilities for identities, endpoints, cloud apps, emails and documents.

When you are ready to migrate:

  1. Onboard the new cloud collector as follows:

  2. Stop the endpoints in the Office 365 Cloud Connector.

Note

Note that duplicate events may occur during the transition period when both collectors are active.