Defender for Cloud is sending empty messages to Event Hub

Yasen Trichkov 0 Reputation points
2025-03-21T14:46:54.0566667+00:00

Hello guys,

We are encountering an unusual issue while configuring Microsoft Defender for Cloud to export its security events to an Azure Event Hub, which we then forward to our SIEM solution for further analysis. We have enabled the Continuous Export feature to facilitate this process. However, despite the configuration appearing correct, when we inspect the logs within the designated Event Hub and its associated Azure Storage account, we find them to be completely empty. There are no incoming events, which suggests that something might be preventing the export from functioning correctly. Could we be missing a critical configuration step or permission setting that is blocking the data flow?

Azure Event Hubs
Azure Event Hubs
An Azure real-time data ingestion service.
711 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Yasen Trichkov 0 Reputation points
    2025-03-25T09:59:36.5533333+00:00

    Hello,

    Thank you for the provided information!

    I'm attaching the configuration of the Continious Export.Screenshot 2025-03-25 at 11.54.03

    Screenshot 2025-03-25 at 11.53.53

    I don't know why but I'm not sure whether Defender for Cloud is generating events at all. Is there a way to browse and view those events in order to confirm that anything to export exists?

    Could you guide me which permission to check both sides? Just to mention - we are exporting logs from Monitor and Entra ID again to Event Hubs and there everything works fine without additional permissions.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.