You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-investigate-all-enterprise-sensor-detections-in-a-device-inventory.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -166,4 +166,4 @@ For more information, see:
166
166
167
167
-[Control what traffic is monitored](how-to-control-what-traffic-is-monitored.md)
168
168
-[Detect Windows workstations and servers with a local script](detect-windows-endpoints-script.md)
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-investigate-sensor-detections-in-a-device-inventory.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -72,21 +72,20 @@ To export device inventory data, on the **Device inventory** page, select **Expo
72
72
73
73
The device inventory is exported with any filters currently applied, and you can save the file locally.
74
74
75
-
To learn about data retention for device inventory, see [Devices retention periods](references-data-retention.md#devices-retention-periods).
76
-
77
75
## Merge devices
78
76
79
77
You may need to merge duplicate devices if the sensor has discovered separate network entities that are associated with a single, unique device.
80
78
81
79
Examples of this scenario might include a PLC with four network cards, a laptop with both WiFi and a physical network card, or a single workstation with multiple network cards.
82
80
83
81
> [!NOTE]
82
+
>
84
83
> - You can only merge authorized devices.
85
84
> - Device merges are irreversible. If you merge devices incorrectly, you'll have to delete the merged device and wait for the sensor to rediscover both devices.
86
85
> - Alternately, merge devices from the [Device map](how-to-work-with-the-sensor-device-map.md) page.
87
86
When merging, you instruct the sensor to combine the device properties of two devices into one. When you do this, the Device Properties window and sensor reports will be updated with the new device property details.
88
87
89
-
For example, if you merge two devices, each with an IP address, both IP addresses will appear as separate interfaces in the Device Properties window.
88
+
For example, if you merge two devices, each with an IP address, both IP addresses will appear as separate interfaces in the Device Properties window.
90
89
91
90
**To merge devices from the device inventory:**
92
91
@@ -98,7 +97,7 @@ For example, if you merge two devices, each with an IP address, both IP addresse
98
97
99
98
## View inactive devices
100
99
101
-
You may want to view devices in your network that have been inactive and delete them.
100
+
You may want to view devices in your network that have been inactive and delete them.
102
101
103
102
For example, devices may become inactive because of misconfigured SPAN ports, changes in network coverage, or by unplugging them from the network
104
103
@@ -178,3 +177,4 @@ For more information, see:
178
177
179
178
-[Control what traffic is monitored](how-to-control-what-traffic-is-monitored.md)
180
179
-[Detect Windows workstations and servers with a local script](detect-windows-endpoints-script.md)
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/references-data-retention.md
+16-15Lines changed: 16 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,9 +17,9 @@ The following table lists how long device data in stored in each Defender for Io
17
17
18
18
| Storage type | Details |
19
19
|---------|---------|
20
-
|**Azure portal**| 90 days from the date of the **Last activity** value.<br><br> For more information, see [Manage your device inventory from the Azure portal](how-to-manage-device-inventory-for-organizations.md). |
21
-
|**OT network sensor**| Device inventory data is stored for 90 days, for all sensors from sensor version 22.3 minor and up. <br><br> For more information, see [Manage your OT device inventory from a sensor console](how-to-investigate-sensor-detections-in-a-device-inventory.md). |
22
-
|**On-promises management console**| Device inventory data is stored for 90 days, depending on the sensor. <br><br> For more information, see [Manage your OT device inventory from an on-premises management console](how-to-investigate-all-enterprise-sensor-detections-in-a-device-inventory.md). |
20
+
|**Azure portal**| 90 days from the date of the **Last activity** value.<br><br> For more information, see [Manage your device inventory from the Azure portal](how-to-manage-device-inventory-for-organizations.md). |
21
+
|**OT network sensor**| Device inventory data is stored with no time limit. <br><br> For more information, see [Manage your OT device inventory from a sensor console](how-to-investigate-sensor-detections-in-a-device-inventory.md). |
22
+
|**On-promises management console**| Device inventory data is stored with no time limit. <br><br> For more information, see [Manage your OT device inventory from an on-premises management console](how-to-investigate-all-enterprise-sensor-detections-in-a-device-inventory.md). |
23
23
24
24
## Alert data retention
25
25
@@ -33,24 +33,23 @@ The following table lists how long alert data in stored in each Defender for IoT
33
33
34
34
### OT alert PCAP data retention
35
35
36
-
The following table lists how long PCAP data is stored in each Defender for IoT location.
36
+
The following table lists how long PCAP data is stored in each Defender for IoT location.
37
37
38
38
| Storage type | Details |
39
39
|---------|---------|
40
40
|**Azure portal**| PCAP files are available for download from the Azure portal for as long as the OT network sensor stores them. <br><br> Once downloaded, the files are cached on the Azure portal for 48 hours. <br><br> For more information, see [Access alert PCAP data (Public preview)](how-to-manage-cloud-alerts.md#access-alert-pcap-data-public-preview). |
41
-
|**OT network sensor**| 90 days, depending on the sensor's storage capacity <!--check this--><br><br>The maximum size of PCAP file storage is set by default to 133,120 MB. If a sensor exceeds this size, the oldest PCAP file is deleted to accommodate the new one.<!--how to change this default?--> <br><br> For more information, see [Download PCAP files](how-to-view-alerts.md#download-pcap-files). |
42
-
|**On-promises management console**| PCAP files aren't stored on the on-premises management console and are only accessed from the on-premises management console via a direct link to the OT sensor. |
41
+
|**OT network sensor**| 90 days, depending on the sensor's storage capacity <br><br>The maximum size of PCAP file storage is set by default to 133,120 MB. If a sensor exceeds this size, the oldest PCAP file is deleted to accommodate the new one. <br><br> For more information, see [Download PCAP files](how-to-view-alerts.md#download-pcap-files). |
42
+
|**On-promises management console**| PCAP files aren't stored on the on-premises management console and are only accessed from the on-premises management console via a direct link to the OT sensor. |
43
43
44
44
## Security recommendation retention
45
45
46
46
Defender for IoT security recommendations are stored only on the Azure portal, for 90 days from when the recommendation is first detected.
47
47
48
-
49
48
For more information, see [Enhance security posture with security recommendations](recommendations.md).
50
49
51
50
## OT event timeline retention
52
51
53
-
OT event timeline data is stored on OT network sensors only, and differs depending on the sensor's [hardware profile](ot-appliance-sizing.md).
52
+
OT event timeline data is stored on OT network sensors only, for as long as there's available storage space, which differs depending on the sensor's [hardware profile](ot-appliance-sizing.md).
54
53
55
54
The following table lists the maximum number of events that can be stored for each hardware profile:
56
55
@@ -68,11 +67,13 @@ For more information, see [Track sensor activity](how-to-track-sensor-activity.m
68
67
69
68
## OT log file retention
70
69
71
-
Only service and processing log files are stored on the Azure portal, and are retained for 30 days.
70
+
Service and processing log files are stored on the Azure portal for 30 days from their creation date.
71
+
72
+
Other OT monitoring log files are stored only on the OT network sensor and the on-premises management console.
72
73
73
-
Other OT network monitoring log files are stored only on the OT network sensor and on-premises management console.
74
+
On both OT sensors and the on-premises management console, files are stored for as long as there's available storage space. When the appliance's storage capacity reaches its maximum, the oldest log files are deleted to make room for the new ones.
74
75
75
-
On both the OT sensor and the on-premises management console, older log files are overridden when the appliance's storage has reached its maximum capacity. Log file sizes differ depending on the amount of content, but the average size per log file is 100-150 MB.
76
+
Log files sizes differ depending on the amount of content, but the average size per log file is 100-150 MB.
76
77
77
78
For more information, see:
78
79
@@ -81,17 +82,17 @@ For more information, see:
81
82
82
83
## On-premises backup file capacity
83
84
84
-
Both the OT network sensor and the on-premises management console have automated backups running daily.
85
-
The following table describes the default maximum sizes for each storage location.
85
+
Both the OT network sensor and the on-premises management console have automated backups running daily.
86
+
The following table describes the default maximum sizes for each storage location.
86
87
87
-
On both the OT sensor and the on-premises management console, older backup files are overridden when the configured storage capacity has reached its maxium.
88
+
On both the OT sensor and the on-premises management console, older backup files are overridden when the configured storage capacity has reached its maximum.
88
89
89
90
For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files
90
91
91
92
| Storage type | Details |
92
93
|---------|---------|
93
94
|**OT network sensor**| The default maximum size of backup files stored on the OT sensor is 100 GB. If you're using an on-premises management console, each connected OT sensor also has its own, extra backup directory on the on-premises management console. |
94
-
|**On-promises management console**| The default maximum size of backup files stored on an on-premises management console are: <br><br>- **On-premises management console backup file**: 10 GB <br> - **OT sensor backup files**, for any connected OT sensor: 40 GB.|
95
+
|**On-promises management console**| The default maximum size of backup files stored on an on-premises management console is: <br><br>- **On-premises management console backup file**: 10 GB <br> - **OT sensor backup files**, for any connected OT sensor: 40 GB.|
0 commit comments