If your organization has deployed a Security Information and Event Management (SIEM) system, you can pull alerts from the Windows Defender ATP portal using the SIEM connector. Connectors are available for multiple vendors, including Splunk and ArcSight. A generic API is available for others.
Go here for more details: https://docs.microsoft.com/en-us/windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.