|
1 | 1 | ---
|
2 |
| -title: Track sensor activity in Defender for IoT |
3 |
| -description: Track sensor activity in the event timeline. |
4 |
| -ms.date: 02/01/2022 |
| 2 | +title: Track network and sensor activity with the event timeline in Microsoft Defender for IoT |
| 3 | +description: Track network and sensor activity in the event timeline. |
| 4 | +ms.date: 02/27/2023 |
5 | 5 | ms.topic: how-to
|
6 | 6 | ---
|
7 | 7 |
|
8 |
| -# Track sensor activity |
| 8 | +# Track network and sensor activity with the event timeline |
9 | 9 |
|
10 |
| -Activity that your sensor detects is recorded in the event timeline. Activity includes alerts and alert actions, network events, and user operations such as user sign in or user deletion. |
| 10 | +Activity detected by your Microsoft Defender for IoT sensors is recorded in the event timeline. Activity includes alerts and alert management actions, network events, and user operations such as user sign-in or user deletion. |
11 | 11 |
|
12 |
| -The event timeline provides a chronological view of events. Use the timeline during investigations, to understand and analyze the chain of events that preceded and followed an attack or incident. |
| 12 | +The event timeline provides a chronological view and context of all network activity, to help determine the cause and effect of incidents. The timeline view makes it easy to extract information from network events, and more efficiently analyze alerts and events observed on the network. With the ability to store vast amounts of data, the event timeline view can be a valuable resource for security teams to perform investigations and gain a deeper understanding of network activity. |
13 | 13 |
|
14 |
| -## Before you start |
| 14 | +Use the event timeline during investigations, to understand and analyze the chain of events that preceded and followed an attack or incident. The centralized view of multiple security-related events on the same timeline helps to identify patterns and correlations, and enable security teams to quickly assess the impact of incidents and respond accordingly. |
15 | 15 |
|
16 |
| -You need to have Administrator or Security Analyst permissions to perform the procedures described in this article. |
| 16 | +Enhance your security analysis and incident investigations with the event timeline, with the following options: |
| 17 | + |
| 18 | +- [View events on the timeline](#view-the-event-timeline) |
| 19 | + |
| 20 | +- [Audit user activity](track-user-activity.md) |
| 21 | + |
| 22 | +- [View and manage alerts](how-to-view-alerts.md#view-details-and-remediate-a-specific-alert) |
| 23 | + |
| 24 | +- [Analyze programming details and changes](how-to-analyze-programming-details-changes.md) |
| 25 | + |
| 26 | +## Permissions |
| 27 | + |
| 28 | +Administrator or Security Analyst permissions are required to perform the procedures described in this article. |
17 | 29 |
|
18 | 30 | ## View the event timeline
|
19 | 31 |
|
20 |
| -1. In Defender for IoT, select **Event Timeline**. |
21 |
| -1. Review the events and filter as needed. |
22 |
| -1. Toggle **User Operations** to hide or show user events. |
23 |
| -1. Select **Add filter** to specify the events shown. |
24 |
| -1. In **Type** filter the events shown using a number of settings: |
25 |
| - - **Event severity**: Show **Alerts Only**, **Alerts and Notices**, or **All Events**. |
26 |
| - - **Device group**: Filter on specific devices defined in the device map. |
27 |
| - - **Include devices**: Search for devices you want to include. |
28 |
| - - **Exclude devices**: Search for devices you want to exclude. |
29 |
| - - **Keywords**: Search for specific keywords. |
30 |
| - - **Include Event Types**: Search for specific event types to include. |
31 |
| - - **Exclude Event Types**: Search for specific event types to exclude. |
32 |
| - - **Date**: Search for events in a specific date range. |
33 |
| -1. Select **Apply* to set the filter. |
34 |
| -1. Select **Export** to export the event timeline to a CSV file. |
35 |
| - |
36 |
| -## Add an event |
| 32 | +1. Sign in to the sensor console, and select **Event Timeline** from the left menu. |
| 33 | + |
| 34 | +1. Review and [filter the events](#filter-events-on-the-timeline) as needed. |
| 35 | + |
| 36 | +1. Select an event row to view the event details in a pane on the right, where you can also filter to view events of related devices. |
| 37 | +The **User Operations** filter is on by default, you can select to hide or show user events as needed. |
| 38 | + |
| 39 | + For example: |
| 40 | + |
| 41 | + :::image type="content" source="media/track-sensor-activity/event-timeline-view-events.png" alt-text="Screenshot of events on the event timeline." lightbox="media/track-sensor-activity/event-timeline-view-events.png"::: |
| 42 | + |
| 43 | +You can also view the event timeline of a specific device from the **Device inventory**. |
| 44 | + |
| 45 | +**To view the event timeline of a specific device**: |
| 46 | + |
| 47 | +1. In the sensor console, go to **Device inventory**. |
| 48 | + |
| 49 | +1. Select the specific device to open the device details pane, and then select **View full details** to open the device properties page. |
| 50 | + |
| 51 | +1. Select the **Event timeline** tab to view all events associated with this device, and [filter the events](#filter-events-on-the-timeline) as needed. |
| 52 | + |
| 53 | + For example: |
| 54 | + |
| 55 | + :::image type="content" source="media/track-sensor-activity/device-properties-page-event-timeline.png" alt-text="Screenshot of event timeline tab in device properties page." lightbox="media/track-sensor-activity/device-properties-page-event-timeline.png"::: |
| 56 | + |
| 57 | +## Filter events on the timeline |
| 58 | + |
| 59 | +1. On the event timeline page, select **Add filter** to specify the events shown. |
| 60 | + |
| 61 | +1. Select the filter **Type**. Use any of the following options to filter the devices shown: |
| 62 | + |
| 63 | + |Type|Description| |
| 64 | + |---|---| |
| 65 | + |**User operations**|This filter is on by default, choose to show or hide user operation events.| |
| 66 | + |**Date**|Search for events in a specific date range.| |
| 67 | + |**Device group**|Filter specific devices by group as defined in the device map.| |
| 68 | + |**Event severity**|Show **Alerts Only**, **Alerts and Notices**, or **All Events**.| |
| 69 | + |**Exclude devices**|Search for and filter devices you want to exclude.| |
| 70 | + |**Include devices**|Search for and filter devices you want to include.| |
| 71 | + |**Exclude Event Types**|Search for and filter specific event types to exclude.| |
| 72 | + |**Include Event Types**|Search for and filter specific event types to include.| |
| 73 | + |**Keywords**|Filter events by specific keywords.| |
| 74 | + |
| 75 | +1. Select **Apply** to set the filter. |
| 76 | + |
| 77 | +## Export the event timeline to CSV |
| 78 | + |
| 79 | +You can export the event timeline to a CSV file, the exported data is according to any filters applied when exporting. |
| 80 | + |
| 81 | +**To export the event timeline**: |
| 82 | + |
| 83 | +On the **Event timeline** page, select **Export** from the top menu to export the event timeline to a CSV file. |
| 84 | + |
| 85 | +## Create an event |
37 | 86 |
|
38 | 87 | In addition to viewing the events that the sensor has detected, you can manually add events to the timeline. This process is useful if an external system event impacts your network, and you want to record it on the timeline.
|
39 | 88 |
|
40 |
| -1. Select **Create Event**. |
41 |
| -1. In the **Create Event** dialog, specify the event type (Info, Notice, or Alert) |
42 |
| -1. Set a timestamp for the event, the device it should be connected with, and provide a description. |
| 89 | +1. On the **Event timeline** page, select **Create Event**. |
| 90 | + |
| 91 | +1. In the **Create Event** dialog, add the following event details: |
| 92 | + |
| 93 | + - **Type**. Specify the event type (Info, Notice, or Alert). |
| 94 | + |
| 95 | + - **Timestamp**. Set the date and time of the event. |
| 96 | + |
| 97 | + - **Device**. Select the device the event should be connected with. |
| 98 | + |
| 99 | + - **Description**. Provide a description of the event. |
| 100 | + |
43 | 101 | 1. Select **Save** to add the event to the timeline.
|
44 | 102 |
|
| 103 | +For example: |
| 104 | + |
| 105 | +:::image type="content" source="media/track-sensor-activity/create-new-event.png" alt-text="Screenshot of creating a new event in the timeline." lightbox="media/track-sensor-activity/create-new-event.png"::: |
| 106 | + |
| 107 | +## Event timeline capacity |
| 108 | + |
| 109 | +The amount of data that can be stored in the event timeline depends on various factors, such as the size of the network, the frequency of events, and the storage capacity of your sensor. The data stored in the event timeline can include information about network traffic, security events, and other relevant data points. |
| 110 | + |
| 111 | +The maximum number of events shown in the event timeline is dependent on [the hardware profile](ot-appliance-sizing.md) selected during sensor installation. Each hardware profile has a maximum capacity of events. For more information on the maximum event capacity for each hardware profile, see [OT event timeline retention](references-data-retention.md#ot-event-timeline-retention). |
| 112 | + |
45 | 113 | ## Next steps
|
46 | 114 |
|
47 |
| -For more information, see: |
| 115 | +[Audit user activity](track-user-activity.md) |
| 116 | + |
| 117 | +[View details and remediate a specific alert](how-to-view-alerts.md#view-details-and-remediate-a-specific-alert) |
48 | 118 |
|
49 |
| -- [View alerts](how-to-view-alerts.md). |
50 |
| -- [OT event timeline retention](references-data-retention.md#ot-event-timeline-retention). |
| 119 | +[Analyze programming details and changes](how-to-analyze-programming-details-changes.md) |
0 commit comments