How to Retrieve Defender Alert-Related Activity via API in Splunk SOAR
Question details
The user needs to retrieve detailed alert-related activities, such as email sender, recipient, and subject, from Microsoft Defender through an API using a Splunk SOAR integration.

- Product
- Microsoft Defender for Cloud / Splunk SOAR
- Device & OS
- not provided
- Scenario
- Pulling comprehensive security alert details and related activities for incident response monitoring in Splunk SOAR.
- Observed behavior
- The current Splunk SOAR integration retrieves alerts and runs Advanced Hunting queries but fails to return the detailed related activity fields shown in the Defender portal.
Ensure you have the necessary API permissions configured in Microsoft Entra ID (formerly Azure AD) to access Microsoft Graph Security endpoints, and verify that your Splunk SOAR integration is up to date.
Utilize the Microsoft Graph Security API
Access the Microsoft 365 Defender APIs in Microsoft Graph to pull detailed investigation data and alert endpoints.
The standard Microsoft Graph REST API provides endpoints dedicated to security alerts. By querying these endpoints directly, you can access the detailed activity logs that may not be exposed by default through basic third-party integrations.
Navigate to the official Microsoft Graph Security API documentation for security alerts to review the available endpoints and required permissions.
Configure your API query to target the security alert endpoint (e.g., GET requests to the /security/alerts_v2 endpoint) to fetch detailed activity information.
Review the returned JSON response to extract and map detailed related activity fields, such as the sender, recipient, and email subject.

Contact Splunk Support for Connector Updates
If the Microsoft Graph API returns the required data but Splunk SOAR does not expose it, the limitation may lie within the third-party connector.
Document Your Security API Workflows with WPS Office
While troubleshooting API endpoints and Splunk SOAR integrations, you need a reliable tool to document your security protocols, API JSON payloads, and incident response plans. WPS Office is a free, lightweight, and fully compatible alternative to Microsoft Office, perfect for drafting comprehensive security documentation.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the on-screen instructions to set up WPS Office on your workstation.
- 3. Create Documentation: Open WPS Writer or WPS Spreadsheet to start documenting your API endpoints, JSON payloads, and integration steps.

Frequently Asked Questions
Why doesn't Splunk SOAR show email sender details from Microsoft Defender?
Splunk SOAR relies on its specific third-party connector and the API endpoints it is configured to use. If the connector is not mapped to fetch or display related activity fields from the Microsoft Graph API, those specific details will not appear in the SOAR dashboard.
What API should I use to get detailed Microsoft Defender alerts?
You should use the Microsoft Graph Security API. Specifically, the Microsoft 365 Defender APIs provide detailed endpoints for security alerts and related investigation data.
Can I run Advanced Hunting queries through Splunk SOAR?
Yes, a Splunk SOAR integration can run Advanced Hunting queries to retrieve Microsoft Defender alerts. However, retrieving deeply nested alert-related activities might require directly querying specific Microsoft Graph REST API endpoints rather than relying solely on the hunting query output.




