
Explanation:
Box 1: Azure Event hub
To stream alerts into //Syslog servers// ,and other monitoring solutions, connect Defender for Cloud using continuous export and Azure Event Hubs.
Box 2: Azure Policy
Note:
To stream alerts at the tenant level, use this //Azure policy// and set the scope at the root management group.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/export-to-siem#stream-alerts-with-continuous-export
https://docs.microsoft.com/en-us/azure/defender-for-cloud/continuous-export?tabs=azure-policy#configure-continuous-export-at-scale-using-the-supplied-policies