You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
:::image type="content" source="media/how-to-work-with-alerts-sensor/custom-alerts-rules.png" alt-text="Screenshot of the Create custom alert rules pane.":::
128
128
129
129
1. Define an alert name.
130
130
1. Select protocol to detect.
131
131
1. Define a message to display. Alert messages can contain alphanumeric characters you enter, as well as traffic variables detected. For example, include the detected source and destination addresses in the alert messages. Use { } to add variables to the message
132
132
1. Select the engine that should detect the activity.
133
-
1.**Select the source and destination devices that pairs for which activity should be detected.**
133
+
1. Select the source and destination devices for the activity you want to detect.
134
134
135
135
#### Create rule conditions
136
136
@@ -165,13 +165,13 @@ Create conditions based on unique values associated with the category selected.
165
165
166
166
8. Enter a **Value** as a number. If the variable you selected is a MAC address or IP address, the value must be converted from a dotted-decimal address to decimal format. Use an IP address conversion tool, for example <https://www.ipaddressguide.com/ip>.
:::image type="content" source="media/how-to-work-with-alerts-sensor/custom-rule-conditions.png" alt-text="Screenshot of the Custom rule condition options.":::
169
169
170
170
9. Select plus (**+**) to create a condition set.
171
171
172
172
When the rule condition or condition set is met, the alert is sent. You will be notified if the condition logic is not valid.
173
173
174
-
**Condition Based when activity took place**
174
+
**Condition based on when activity took place**
175
175
176
176
Create conditions based on when the activity was detected. In the Detected section, select a time period and day in which the detection must occur in order to send the alert. You can choose to send the alert if the activity is detected:
177
177
- any time throughout the day
@@ -191,7 +191,7 @@ The following actions can be defined for the rule:
191
191
192
192
The rule is added to the **Customized Alerts Rules** page.
193
193
194
-
:::image type="content" source="media/how-to-work-with-alerts-sensor/custom-alerts-page.png" alt-text="Custom alerts main page" lightbox="media/how-to-work-with-alerts-sensor/custom-alerts-page.png":::
194
+
:::image type="content" source="media/how-to-work-with-alerts-sensor/custom-alerts-page.png" alt-text="Screenshot of the main Custom alerts page." lightbox="media/how-to-work-with-alerts-sensor/custom-alerts-page.png":::
195
195
196
196
### Managing customer alert rules
197
197
@@ -213,6 +213,6 @@ Changes made to custom alert rules are tracked in the event timeline. For exampl
213
213
1. Navigate to the Event timeline page.
214
214
215
215
216
-
### See also
216
+
##Next steps
217
217
218
-
[Manage the alert event](how-to-manage-the-alert-event.md)
218
+
For more information, see [Manage the alert event](how-to-manage-the-alert-event.md).
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-activate-and-set-up-your-on-premises-management-console.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -364,6 +364,6 @@ To unassign and delete a sensor:
364
364
365
365
1. To delete the unassigned sensor from the site, select the sensor from the list of unassigned sensors and select :::image type="icon" source="media/how-to-activate-and-set-up-your-on-premises-management-console/delete-icon.png" border="false":::.
366
366
367
-
## See also
367
+
## Next steps
368
368
369
-
[Troubleshoot the sensor and on-premises management console](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md)
369
+
For more information, see [Troubleshoot the sensor and on-premises management console](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md).
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-activate-and-set-up-your-sensor.md
+21-19Lines changed: 21 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -46,7 +46,7 @@ Your sensor was onboarded to Microsoft Defender for IoT in a specific management
46
46
47
47
A locally connected, or cloud-connected activation file was generated and downloaded for this sensor during onboarding. The activation file contains instructions for the management mode of the sensor. *A unique activation file should be uploaded to each sensor you deploy.* The first time you sign in, you need to upload the relevant activation file for this sensor.
48
48
49
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/azure-defender-for-iot-activation-file-download-button.png" alt-text="Defender for IoT in the Azure portal, onboard sensor.":::
49
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/azure-defender-for-iot-activation-file-download-button.png" alt-text="Screenshot of the download activation file for Defender for IoT sensors in the Azure portal.":::
50
50
51
51
### About certificates
52
52
@@ -76,15 +76,15 @@ For more information about working with certificates, see [Manage certificates](
76
76
77
77
1. Go to the sensor console from your browser by using the IP defined during the installation. The sign-in dialog box opens.
78
78
79
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-1.png" alt-text="Sensor log in screen":::
79
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-1.png" alt-text="Screenshot of a Defender for IoT sensor sign in page.":::
80
80
81
81
82
82
1. Enter the credentials defined during the sensor installation, or select the **Password recovery** option. If you purchased a preconfigured sensor from Arrow, generate a password first. For more information on password recovery, see [Investigate password failure at initial sign-in](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md#investigate-password-failure-at-initial-sign-in).
83
83
84
84
85
85
1. Select **Login/Next**. The **Sensor Network Settings** tab opens.
86
86
87
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-wizard-activate.png" alt-text="log in to sensor":::
87
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-wizard-activate.png" alt-text="Screenshot of the sensor network settings options when signing into the sensor.":::
88
88
89
89
1. Use this tab if you want to change the sensor network configuration before activation. The configuration parameters were defined during the software installation, or when you purchased a preconfigured sensor. The following parameters were defined:
90
90
@@ -98,11 +98,11 @@ For more information about working with certificates, see [Manage certificates](
98
98
99
99
If you want to work with a proxy, enable the proxy toggle and add the proxy host, port and username.
100
100
101
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-wizard-activate-proxy.png" alt-text="Initial Log in to sensor using a proxy":::
101
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-wizard-activate-proxy.png" alt-text="Screenshot of the proxy options for signing in to a sensor.":::
102
102
103
103
1. Select **Next.** The Activation tab opens.
104
104
105
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/wizard-upload-activation-file.png" alt-text="First time log in activation file":::
105
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/wizard-upload-activation-file.png" alt-text="Screenshot of a first time activation file upload option.":::
106
106
107
107
1. Select **Upload** and go to the activation file that you downloaded during the sensor onboarding.
108
108
@@ -112,7 +112,7 @@ For more information about working with certificates, see [Manage certificates](
112
112
113
113
It is **not recommended** to use a locally generated certificate in a production environment.
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/wizard-upload-activation-certificates-1.png" alt-text="Screenshot of the SSL/TLS Certificates page when signing in to a sensor.":::
116
116
117
117
1. Enable the **Import trusted CA certificate (recommended)** toggle.
118
118
1. Define a certificate name.
@@ -131,7 +131,7 @@ For information about uploading a new certificate, supported certificate paramet
131
131
132
132
For users with versions prior to 10.0, your license may expire, and the following alert will be displayed.
133
133
134
-
:::image type="content" source="media/how-to-activate-and-set-up-your-on-premises-management-console/activation-popup.png" alt-text="When your license expires you’ll need to update your license through the activation file.":::
134
+
:::image type="content" source="media/how-to-activate-and-set-up-your-on-premises-management-console/activation-popup.png" alt-text="Screenshot of a license expiration popup message.":::
135
135
136
136
**To activate your license:**
137
137
@@ -145,19 +145,19 @@ For users with versions prior to 10.0, your license may expire, and the followin
145
145
146
146
1. Paste the string into space provided.
147
147
148
-
:::image type="content" source="media/how-to-activate-and-set-up-your-on-premises-management-console/add-license.png" alt-text="Paste the string into the provided field.":::
148
+
:::image type="content" source="media/how-to-activate-and-set-up-your-on-premises-management-console/add-license.png" alt-text="Screenshot of the license activation box and button.":::
149
149
150
150
1. Select **Activate**.
151
151
152
152
### Subsequent sign ins
153
153
154
154
After first-time activation, the Microsoft Defender for IoT sensor console opens after sign-in without requiring an activation file or certificate definition. You only need your sign-in credentials.
155
155
156
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-1.png" alt-text="Sensor login after initial activation":::
156
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-1.png" alt-text="Screenshot of the sensor sign in page after the initial activation.":::
157
157
158
158
After your sign in, the Microsoft Defender for IoT sensor console opens.
159
159
160
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/initial-dashboard.png" alt-text="Screenshot that shows the Defender for IoT initial dashboard." lightbox="media/how-to-activate-and-set-up-your-sensor/initial-dashboard.png":::
160
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/initial-dashboard.png" alt-text="Screenshot of the initial sensor console dashboard Overview page." lightbox="media/how-to-activate-and-set-up-your-sensor/initial-dashboard.png":::
161
161
162
162
## Initial setup and learning (for administrators)
163
163
@@ -198,7 +198,7 @@ Before you sign in, verify that you have:
198
198
- The sensor IP address.
199
199
- Sign in credentials that your administrator provided.
200
200
201
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-1.png" alt-text="Sensor login after initial setup":::
201
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/sensor-log-in-1.png" alt-text="Screenshot of the sensor sign in page after the initial setup.":::
202
202
203
203
204
204
## Console tools: Overview
@@ -209,13 +209,13 @@ You can access console tools from the side menu. Tools help you:
209
209
- Set up your sensor for maximum performance
210
210
- Create and manage users
211
211
212
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/main-page-side-bar.png" alt-text="The main menu of the sensor console on the left side of the screen":::
212
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/main-page-side-bar.png" alt-text="Screenshot of the sensor console's main menu on the left.":::
213
213
214
214
### Discover
215
215
216
216
| Tools| Description |
217
217
| -----------|--|
218
-
| Overview | View a dashboard with high-level information about your sensor deployment, alerts, traffic, and more. <!--- For more information, see TBD --->|
218
+
| Overview | View a dashboard with high-level information about your sensor deployment, alerts, traffic, and more. |
219
219
| Device map | View the network devices, device connections, Purdue levels, and device properties in a map. Various zoom, highlight, and filter options are available to help you gain the insight you need. For more information, see [Investigate sensor detections in the Device Map](how-to-work-with-the-sensor-device-map.md#investigate-sensor-detections-in-the-device-map). |
220
220
| Device inventory | The Device inventory displays a list of device attributes that this sensor detects. Options are available to: <br /> - Sort, or filter the information according to the table fields, and see the filtered information displayed. <br /> - Export information to a CSV file. <br /> - Import Windows registry details. For more information, see [Investigate sensor detections in a device inventory](how-to-investigate-sensor-detections-in-a-device-inventory.md#investigate-sensor-detections-in-an-inventory).|
221
221
| Alerts | Alerts are triggered when sensor engines detect changes or suspicious activity in network traffic that require your attention. For more information, see [View alerts on your sensor](how-to-view-alerts.md#view-alerts-on-your-sensor).|
@@ -253,19 +253,21 @@ You can access console tools from the side menu. Tools help you:
253
253
- your sensor isn't detecting traffic
254
254
- your sensor SSL certificate is expired or will expire soon
255
255
256
-
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/system-messages.png" alt-text="System messages screen on main sensor console page, viewed by selecting the bell icon":::
256
+
:::image type="content" source="media/how-to-activate-and-set-up-your-sensor/system-messages.png" alt-text="Screenshot of the System messages area on the sensor console page, displayed after selecting the bell icon.":::
257
257
258
258
**To review system messages:**
259
259
1. Sign into the sensor
260
260
1. Select the **System Messages** icon (Bell icon).
261
261
262
262
263
-
## See also
263
+
## Next steps
264
264
265
-
[Threat intelligence research and packages ](how-to-work-with-threat-intelligence-packages.md)
265
+
For more information, see:
266
266
267
-
[Onboard a sensor](getting-started.md#onboard-a-sensor)
267
+
-[Threat intelligence research and packages ](how-to-work-with-threat-intelligence-packages.md)
:::image type="content" source="media/how-to-work-with-maps/compare.png" alt-text="Screenshot of the compare indicator.":::
116
116
117
117
The window displays all dates the selected file was detected on the programmed device. The file may have been updated on the programmed device by multiple programming devices.
118
118
119
119
The number of differences detected appears in the upper right-hand corner of the window. You may need to scroll down to view differences.
120
120
121
-
:::image type="content" source="media/how-to-work-with-maps/scroll.png" alt-text="scroll down to your selection":::
121
+
:::image type="content" source="media/how-to-work-with-maps/scroll.png" alt-text="Screenshot of scrolling down to your selection.":::
122
122
123
123
The number is calculated by adjacent lines of changed text. For example, if eight consecutive lines of code were changed (deleted, updated, or added) this will be calculated as one difference.
:::image type="content" source="media/how-to-work-with-maps/program-timeline.png" alt-text="Screenshot of the programming timeline view." lightbox="media/how-to-work-with-maps/program-timeline.png":::
126
126
127
127
4. Select a date. The file detected on the selected date appears in the window.
128
128
@@ -135,4 +135,8 @@ In addition to reviewing details in the Programming Timeline, you can access pro
135
135
| Device type | Description |
136
136
|--|--|
137
137
| Device properties | The device properties window provides information on the last programming event detected on the device. |
138
-
| The device inventory | The device inventory indicates if the device is a programming device. <br> :::image type="content" source="media/how-to-work-with-maps/inventory-v2.png" alt-text="The inventory of devices"::: |
138
+
| The device inventory | The device inventory indicates if the device is a programming device. <br> :::image type="content" source="media/how-to-work-with-maps/inventory-v2.png" alt-text="Screenshot of the device inventory page."::: |
139
+
140
+
## Next steps
141
+
142
+
For more information, see [Import device information to a sensor](how-to-import-device-information.md).
0 commit comments