Microsoft Defender - Rapid7 Agent vs Event Source

If we were to have endpoints that are running Microsoft Defender Endpoint and also the Rapid7 Insight/IDR agent, is setting up the event source from our Microsoft Defender console going to create a duplication of logs. Assuming the Rapid7 will just send the same events to the IDR as the console would.

It isn't a direct duplication of data as they would be unique data streams, however there may be some overlap.

Ootb the insight agent collects Windows Defender Antivirus logs, which can produce generic virus alert detections, whereas the Windows Defender for endpoint is a different product offering which encompasses more than just AV.