> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/listeners/listener-integrations/collect-data-using-http/collect-data-from-microsoft-defender-for-cloud-apps-via-http.md).

# Collect data from Microsoft Defender for Cloud Apps via HTTP

{% hint style="info" %}
See the changelog of the **HTTP** Listener [here](/listeners-changelog/http-listener.md).
{% endhint %}

## Overview

The following article outlines a basic data flow from [Microsoft Defender for Cloud Apps](https://learn.microsoft.com/en-us/defender-cloud-apps/what-is-defender-for-cloud-apps) to the Onum **HTTP** Listener.

## Prerequisites

* Administrative access to the Microsoft Defender for Cloud Apps portal

[Contact Onum](broken://spaces/cSjT21I4EUhzghjc1rER/pages/nW8oZycpfVthtI5KYdQs) to get the required JWT token, which will be needed on the Listener setup.&#x20;

You can also contact us if you cannot generate the required TLS certificates. Note that these certificates must be signed by a recognized Certificate Authority (CA). Self-signed certificates are not accepted.

## Defender for Cloud Apps Setup

Microsoft Defender for Cloud Apps (MDCA) can be configured to send logs to Onum. Here's how to set it up:

1. Access [Microsoft Defender for Cloud Apps](https://portal.cloudappsecurity.com)
2. Go to **Settings** > **Security extensions**

* Select **SIEM agents** tab
* Click **Add SIEM agent**

&#x20;3\. Set Up the SIEM Agent

* Choose **Generic SIEM** as the SIEM type
* Enter a name for the connection (e.g., Onum Integration)
* Select the data types you want to send:
  * Alerts
  * Activities
  * Discovery data (if applicable)
* Configure the remote SIEM server:
  * Protocol: HTTPS
  * Host: Your Onum domain (e.g., `https://[your-onum-tenant].onum.ai/api/ingest`)
  * Port: 443 (standard HTTPS)
  * URL path: Your configured path (e.g., `/ingest/mdca`)

4. Configure Authentication

* Select the appropriate authentication method. In this case, we will exemplify the **bearer** method.
* Specify the log format (JSON is recommended)

## Important Considerations Regarding Cloud Listeners

* In cloud-based Onum installations, the **TLS** configuration section of the HTTP Listener is not visible and you won't need to enter these values. In these setups, Onum automatically manages TLS certificates, eliminating the need for manual configuration. If your HTTP Listener configuration requires you to manually enter these TLS certificates, you can generate them following the instructions [in this article](https://docs.onum.com/usecases/routing/crowdstrike-integration/self-signed-ssl-tls-certificates-creation).
* If you are defining this Listener in a cloud instance, Onum will automatically provide the **Port** and **TLS** configuration.&#x20;
* Cloud Listeners have an additional step in their creation process: **Network configuration**. Use these details to configure your data source to communicate with Onum. Click **Download certificate** to get the required certificate for the connection. You can also download it from the Listener details once it is created.
* When configuring a Listener in a Cloud tenant, the **port** will be `443`. In on-prem, the selected port must fall within the range of `1024` to `10000`.
* Cloud Listener endpoints are created in Onum's DNS. This process is usually fast, and Listeners are normally available immediately. However, note that this may last up to 24-48 hours, depending on your organization's DNS configuration.
* Your data input must use the **Server Name Indication (SNI)** method, which means it must send its hostname in the TLS authentication process. If SNI is not used, the certificate routing will fail, and data will not be received, even if the certificate is valid.

If your organization's software cannot meet points 2 and 3, you can use an intermediate piece of software to ensure the client-Onum connection, such as Stunnel.

## Onum Setup

Here we will detail the steps for the **HTTP** Listene&#x72;**.**

{% stepper %}
{% step %}
Log in to your Onum tenant and click **Listeners > New listener**.
{% endstep %}

{% step %}
Double-click the **HTTP** Listener.
{% endstep %}

{% step %}
Enter a **Name** for the new Listener. Optionally, add a **Description** and some **Tags** to identify the Listener.
{% endstep %}

{% step %}
For most cloud-based Onum installations, the **Socket** section is not visible, and **port** `443` is used by default. If you see it, enter the required port in the **Port** field. At this time, all TCP ports from `1024` to `10000` are open.
{% endstep %}

{% step %}
In most cloud-based Onum installations, the **TLS** configuration section is not visible. In these setups, Onum automatically manages **TLS** certificates, eliminating the need for manual configuration.&#x20;

If you see this section, you must enter the required **Certificate**, **Private key** and **CA Chain.** Learn how to generate these self-signed certificates in [this article](https://docs.onum.com/usecases/routing/crowdstrike-integration/self-signed-ssl-tls-certificates-creation). Once you have them, click **New secret** in each field and add the corresponding values.
{% endstep %}

{% step %}
**Now there are two possible scenarios:**

If you didn't enter your **TLS** certificates, when you click **Create listener** you'll see the **Network configuration** screen, which shows the **Address** and **Port** needed to communicate with Onum. Here you will download the certificate (see the[ steps after creation to do this](#download-certificate)).

{% hint style="info" %}
You can access all this information in the Listener details after creation, so don't worry.
{% endhint %}

If you entered the TLS certificates, you'll go directly to the Labels when you eventually click **create Listener**.
{% endstep %}

{% step %}
In the **Authentication** section, choose **Bearer** as the Authentication Type.&#x20;

Open the Token Secret field and click New secret to create a new one:

* Give the token a **Name**.
* Turn off the **Expiration** **date** option.
* Click **Add new value** and paste the secret corresponding to the JWT token you received. Remember that the token will be added in the Cloudflare configuration.
* Click **Save**.

{% hint style="info" %}
Learn more about secrets in Onum [in this article.](/settings/organization-settings/secrets-management.md)
{% endhint %}

You can now select the secret you just created in the Token Secret field.
{% endstep %}

{% step %}
In the **Endpoint** section, choose `POST` as the **HTTP Method**.&#x20;

In the **Request path** field, you're creating an endpoint where MDCA will send data.

#### Standard Format

```
/ingest/mdca<meta charset='utf-8'><div class="max-w-[--block-wrapper-max-width] w-full mx-auto" data-render-mode="unstyled" style="--block-max-width: calc(var(--page-layout-default-max-width) - var(--block-margin-x) * 2);"><div class="flex flex-col"><div data-key="X6hb5AIJHA5u" class="group/drop-target relative flex w-full pt-6 pb-2 _dropHorizontal_tah5q_27" style="justify-content: flex-start;"><div data-block-content="X6hb5AIJHA5u" class="relative flex-1 max-w-[--block-wrapper-max-width] peer-hover:block-highlight-hover group-data-[drop-on]/drop-target:block-drop-target"><h4 id="standard-format" class="heading relative flex justify-start group/block-anchor"><span id="text-standard-format" class="relative min-w-px select-text text-left text-content-paragraph md:text-content-heading-small"><span data-key="F1Snjlnh3L7J"><span data-offset-key="F1Snjlnh3L7J:0">Standard Format</span></span></span></h4></div></div></div></div><div class="max-w-[--block-wrapper-max-width] w-full mx-auto" data-render-mode="unstyled" style="--block-max-width: calc(var(--page-layout-default-max-width) - var(--block-margin-x) * 2);" data-slate-fragment="JTdCJTIyb2JqZWN0JTIyJTNBJTIyZG9jdW1lbnQlMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJoZWFkaW5nLTMlMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMlN0YW5kYXJkJTIwRm9ybWF0JTIyJTJDJTIybWFya3MlMjIlM0ElNUIlNUQlN0QlNUQlMkMlMjJrZXklMjIlM0ElMjIzQnBCRUMxOWFBSzIlMjIlN0QlNUQlMkMlMjJrZXklMjIlM0ElMjJKRTU4VW1JNnJFb04lMjIlN0QlMkMlN0IlMjJvYmplY3QlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJjb2RlJTIyJTJDJTIyaXNWb2lkJTIyJTNBZmFsc2UlMkMlMjJkYXRhJTIyJTNBJTdCJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJjb2RlLWxpbmUlMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiUyRmluZ2VzdCUyRm1kY2ElMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCUyQyUyMmtleSUyMiUzQSUyMnFGdmdxQnlWM1ZpYSUyMiU3RCU1RCUyQyUyMmtleSUyMiUzQSUyMlpxSlVJVGpUV1pSRiUyMiU3RCU1RCUyQyUyMmtleSUyMiUzQSUyMnF6UGFjVlRyZjBNdCUyMiU3RCU1RCUyQyUyMmtleSUyMiUzQSUyMk9jQTVKWWZHVmw3UCUyMiU3RA=="><div class="flex flex-col"><div data-key="qzPacVTrf0Mt" class="group/drop-target relative flex w-full pt-4 pb-0 _dropHorizontal_tah5q_27" style="justify-content: flex-start;"><span contenteditable="false" aria-hidden="true" tabindex="-1" class="pointer-events-none absolute inset-y-0 select-none" style="left: 0px; right: -16px;">​</span><div data-block-content="qzPacVTrf0Mt" class="relative flex-1 max-w-[--block-wrapper-max-width] peer-hover:block-highlight-hover group-data-[drop-on]/drop-target:block-drop-target"><div class="group/code-block relative w-full select-none rounded border border-base bg-[--shiki-background] py-2"><div class="w-full overflow-auto" id=":r2643:"><div translate="no" spellcheck="false" class="grid w-full grid-cols-[auto_minmax(0,_1fr)] [count-reset:line] [tab-size:2] print:whitespace-pre-wrap min-w-max"><div data-key="ZqJUITjTWZRF" class="group/code-block-line col-span-2 grid min-w-full select-none grid-cols-subgrid font-medium font-mono text-ui-base leading-6 whitespace-pre pr-4 hover:bg-neutral-ui-hover"><div class="group/code-block-line-gutter relative flex w-full min-w-0 select-none justify-end pr-3 pl-2 cursor-pointer" contenteditable="false">​<div class="invisible absolute inset-0 flex bg-neutral-ui-active pt-[0.5lh] pl-0.75 opacity-0 transition-discrete transition-opacity group-hover/code-block-line-gutter:visible group-hover/code-block-line-gutter:opacity-100"><label data-react-aria-pressable="true" class="data-[focus-visible]:focus-ring flex shrink-0 items-center justify-center border transition-colors ease-snappy-out relative size-3.5 rounded cursor-pointer border-neutral-subtle bg-neutral-ui -translate-y-1/2" data-rac=""><span style="border: 0px; clip: rect(0px, 0px, 0px, 0px); clip-path: inset(50%); height: 1px; margin: -1px; overflow: hidden; padding: 0px; position: absolute; width: 1px; white-space: nowrap;"><input type="checkbox" data-react-aria-pressable="true" tabindex="0" title=""></span><svg xmlns="http://www.w3.org/2000/svg" fill="none" viewBox="0 0 16 16" class="undefined _tickHidden_12uq6_19" style="vertical-align: middle; width: 1em; height: 1em;"><path d="M3 8L6.5 12L13 4" stroke="currentColor" stroke-width="1.2" stroke-linecap="round" stroke-linejoin="round" class="_tickPath_12uq6_1"></path></svg></label></div></div><div class="w-full min-w-0 select-text"><span data-key="qFvgqByV3Via"><span data-offset-key="qFvgqByV3Via:0">/ingest/mdca</span></span></div></div></div></div></div></div></div></div></div>
```

{% endstep %}

{% step %}
In the **Message extraction** section, choose **Single event as body (full)** in the Strategy field.
{% endstep %}

{% step %}
In the **General behavior** section, set **Propagate headers strategy** to **Allow**.
{% endstep %}

{% step %}
Then, configure the following settings:

* `Content-Enconding`
* `Content-Type`
  {% endstep %}

{% step %}
For cloud installments, copy the **DNS Address** details to configure your data source in order to communicate with Onum. This contains the IP address of the DNS (Domain Name System) server to connect to.

{% hint style="warning" %}
Note that you will only see this section if you're defining this Listener in a Cloud instance.&#x20;
{% endhint %}
{% endstep %}

{% step %}
Finally, click **Create labels**. Optionally, you can set labels to be used for internal Onum routing of data. By default, data will be set as **Unlabeled**. Click **Create listener** when you're done.

{% hint style="info" %}
Learn more about labels in [this article](/listeners/labels.md).
{% endhint %}
{% endstep %}
{% endstepper %}

Click **Create listener** when you're done.

### Download certificate

For cloud environments, download the certificate from the **Listeners** view by clicking the created listener and selecting the three dots in the top right-hand corner of the menu > **Download Certificate**.

{% hint style="info" %}
This .p12 does not require password to access.
{% endhint %}

To extract the certificates from the download:

```
#!/bin/bash
# Extract certs from certificate.p12

# Client certificate (PEM)
openssl pkcs12 -in certificate.p12 -clcerts -nokeys -out client.crt -password pass:

# Client private key (PEM)
openssl pkcs12 -in certificate.p12 -nocerts -nodes -out client.key -password pass:

# CA chain (PEM)
openssl pkcs12 -in certificate.p12 -cacerts -nokeys -out ca-chain.crt -password pass:
```

### Ports <a href="#ports" id="ports"></a>

The HTTP Listener has two output ports:

* **Default port** - Events are sent through this port if no error occurs while processing them.
* **Error port** - Events are sent through this port if an error occurs while processing them.

{% hint style="warning" %}
The error message is provided in a free-text format and may change over time. Please consider this if performing any post-processing based on the message content.
{% endhint %}
