Hi,
I'm trying to get Defender AV log from Azure VM (2016) to log analytics but I can't find play where configure it. When trying to add Defender AV log from Log Anaytics -> Advanced settings -> Windows Event Logs -> and type "Windows Defender" or "Defender" I can't find the "Path" or ways to add that to the collected logs list . If i go to VM and go to Event Event Viewer >> Applications and Services Logs >> Microsoft >> Windows >> Windows Defender >> Operational I can see that there all a lot of events.
I tried also searched "SecurityEvent" table with Defender AV IDs but could not found a single event. Any tips how to get those infos into workspace?