You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/file-integrity-monitoring-enable-ama.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -59,11 +59,11 @@ To enable File Integrity Monitoring (FIM):
59
59
60
60
1. From Defender for Cloud's sidebar, go to **Workload protections** > **File integrity monitoring**, and select the banner to show the results for machines with Azure Monitor Agent.
61
61
62
-
:::image type="content" source="media/file-integrity-monitoring-enable-ama/fim-ama-banner.png" alt-text="Screenshot of banner in File integrity monitoring to show the results for machines with Azure Monitor Agent.":::
62
+
:::image type="content" source="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-banner.png" alt-text="Screenshot of banner in File integrity monitoring to show the results for machines with Azure Monitor Agent.":::
63
63
64
64
1. The machines with File Integrity Monitoring enabled are shown.
65
65
66
-
:::image type="content" source="media/file-integrity-monitoring-enable-ama/fim-ama-results.png" alt-text="Screenshot of File integrity monitoring results for machines with Azure Monitor Agent." lightbox="media/file-integrity-monitoring-enable-ama/fim-ama-results.png":::
66
+
:::image type="content" source="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-results.png" alt-text="Screenshot of File integrity monitoring results for machines with Azure Monitor Agent." lightbox="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-results.png":::
67
67
68
68
You can see the number of changes that were made to the tracked files, and you can select **View changes** to see the changes made to the tracked files on that machine.
69
69
@@ -97,7 +97,7 @@ To exclude a machine from File Integrity Monitoring:
97
97
98
98
- In the list of monitored machines in the FIM results, select the menu (**...**) for the machine and select **Detach data collection rule**.
99
99
100
-
:::image type="content" source="media/file-integrity-monitoring-enable-ama/fim-ama-detach-rule.png" alt-text="Screenshot of the option to detach a machine from a data collection rule and exclude the machines from File Integrity Monitoring." lightbox="media/file-integrity-monitoring-enable-ama/fim-ama-detach-rule.png":::
100
+
:::image type="content" source="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-detach-rule.png" alt-text="Screenshot of the option to detach a machine from a data collection rule and exclude the machines from File Integrity Monitoring." lightbox="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-detach-rule.png":::
101
101
102
102
The machine moves to the list of unmonitored machines, and file changes aren't tracked for that machine anymore.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/file-integrity-monitoring-enable-log-analytics.md
+14-14Lines changed: 14 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -30,7 +30,7 @@ FIM is only available from Defender for Cloud's pages in the Azure portal. There
30
30
31
31
1. From the **Workload protections** dashboard's **Advanced protection** area, select **File integrity monitoring**.
32
32
33
-
:::image type="content" source="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png" alt-text="Screenshot of opening the File Integrity Monitoring dashboard." lightbox="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png":::
33
+
:::image type="content" source="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png" alt-text="Screenshot of screenshot of opening the File Integrity Monitoring dashboard." lightbox="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png":::
34
34
35
35
The following information is provided for each workspace:
36
36
@@ -47,14 +47,14 @@ FIM is only available from Defender for Cloud's pages in the Azure portal. There
47
47
48
48
-![Enable icon][3] Enable FIM on all machines under the workspace and configure the FIM options. This icon indicates that FIM is not enabled for the workspace.
49
49
50
-
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-list-fim.png" alt-text="Enabling FIM for a specific workspace.":::
50
+
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-list-fim.png" alt-text="Screenshot of enabling FIM for a specific workspace.":::
51
51
52
52
> [!TIP]
53
53
> If there's no enable or upgrade button, and the space is blank, it means that FIM is already enabled on the workspace.
54
54
55
55
1. Select **ENABLE**. The details of the workspace including the number of Windows and Linux machines under the workspace is shown.
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-fim-status.png" alt-text="Screenshot of FIM workspace details page.":::
58
58
59
59
The recommended settings for Windows and Linux are also listed. Expand **Windows files**, **Registry**, and **Linux files** to see the full list of recommended items.
60
60
@@ -73,7 +73,7 @@ To disable FIM:
73
73
74
74
1. From the **File Integrity Monitoring dashboard** for a workspace, select **Disable**.
75
75
76
-
:::image type="content" source="./media/file-integrity-monitoring-overview/disable-file-integrity-monitoring.png" alt-text="Disable file integrity monitoring from the settings page.":::
76
+
:::image type="content" source="./media/file-integrity-monitoring-overview/disable-file-integrity-monitoring.png" alt-text="Screenshot of disabling file integrity monitoring from the settings page.":::
77
77
78
78
1. Select **Remove**.
79
79
@@ -83,7 +83,7 @@ To disable FIM:
83
83
84
84
The **File integrity monitoring** dashboard displays for workspaces where FIM is enabled. The FIM dashboard opens after you enable FIM on a workspace or when you select a workspace in the **file integrity monitoring** window that already has FIM enabled.
85
85
86
-
:::image type="content" source="./media/file-integrity-monitoring-overview/fim-dashboard.png" alt-text="The FIM dashboard and its various informational panels.":::
86
+
:::image type="content" source="./media/file-integrity-monitoring-overview/fim-dashboard.png" alt-text="Screenshot of the FIM dashboard and its various informational panels.":::
87
87
88
88
The FIM dashboard for a workspace displays the following details:
89
89
@@ -94,7 +94,7 @@ The FIM dashboard for a workspace displays the following details:
94
94
95
95
Select **Filter** at the top of the dashboard to change the time period for which changes are shown.
96
96
97
-
:::image type="content" source="./media/file-integrity-monitoring-overview/dashboard-filter.png" alt-text="Time period filter for the FIM dashboard.":::
97
+
:::image type="content" source="./media/file-integrity-monitoring-overview/dashboard-filter.png" alt-text="Screenshot of time period filter for the FIM dashboard.":::
98
98
99
99
The **Servers** tab lists the machines reporting to this workspace. For each machine, the dashboard lists:
100
100
@@ -103,7 +103,7 @@ The **Servers** tab lists the machines reporting to this workspace. For each mac
103
103
104
104
When you select a machine, the query appears along with the results that identify the changes made during the selected time period for the machine. You can expand a change for more information.
105
105
106
-
:::image type="content" source="./media/file-integrity-monitoring-overview/query-machine-changes.png" alt-text="Log Analytics query showing the changes identified by Microsoft Defender for Cloud's file integrity monitoring" lightbox="./media/file-integrity-monitoring-overview/query-machine-changes.png":::
106
+
:::image type="content" source="./media/file-integrity-monitoring-overview/query-machine-changes.png" alt-text="Screenshot of log Analytics query showing the changes identified by Microsoft Defender for Cloud's file integrity monitoring." lightbox="./media/file-integrity-monitoring-overview/query-machine-changes.png":::
107
107
108
108
The **Changes** tab (shown below) lists all changes for the workspace during the selected time period. For each entity that was changed, the dashboard lists the:
109
109
@@ -112,17 +112,17 @@ The **Changes** tab (shown below) lists all changes for the workspace during the
:::image type="content" source="./media/file-integrity-monitoring-overview/changes-tab.png" alt-text="Screenshot of Microsoft Defender for Cloud's file integrity monitoring changes tab." lightbox="./media/file-integrity-monitoring-overview/changes-tab.png":::
116
116
117
117
**Change details** opens when you enter a change in the search field or select an entity listed under the **Changes** tab.
118
118
119
-
:::image type="content" source="./media/file-integrity-monitoring-overview/change-details.png" alt-text="Microsoft Defender for Cloud's file integrity monitoring showing the details pane for a change" lightbox="./media/file-integrity-monitoring-overview/change-details.png":::
119
+
:::image type="content" source="./media/file-integrity-monitoring-overview/change-details.png" alt-text="Screenshot of Microsoft Defender for Cloud's file integrity monitoring showing the details pane for a change." lightbox="./media/file-integrity-monitoring-overview/change-details.png":::
120
120
121
121
### Edit monitored entities
122
122
123
123
1. From the **File Integrity Monitoring dashboard** for a workspace, select **Settings** from the toolbar.
124
124
125
-
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png" alt-text="Accessing the file integrity monitoring settings for a workspace." lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png":::
125
+
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png" alt-text="Screenshot of accessing the file integrity monitoring settings for a workspace." lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png":::
126
126
127
127
**Workspace Configuration** opens with tabs for each type of element that can be monitored:
128
128
@@ -134,7 +134,7 @@ The **Changes** tab (shown below) lists all changes for the workspace during the
134
134
135
135
Each tab lists the entities that you can edit in that category. For each entity listed, Defender for Cloud identifies whether FIM is enabled (true) or not enabled (false). Edit the entity to enable or disable FIM.
136
136
137
-
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-workspace-configuration.png" alt-text="Workspace configuration for file integrity monitoring in Microsoft Defender for Cloud.":::
137
+
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-workspace-configuration.png" alt-text="Screenshot of workspace configuration for file integrity monitoring in Microsoft Defender for Cloud.":::
138
138
139
139
1. Select an entry from one of the tabs and edit any of the available fields in the **Edit for Change Tracking** pane. Options include:
140
140
@@ -158,7 +158,7 @@ The **Changes** tab (shown below) lists all changes for the workspace during the
158
158
159
159
In this example, we selected **Linux Files**.
160
160
161
-
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png" alt-text="Adding an element to monitor in Microsoft Defender for Cloud's file integrity monitoring" lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png":::
161
+
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png" alt-text="Screenshot of adding an element to monitor in Microsoft Defender for Cloud's file integrity monitoring." lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png":::
162
162
163
163
1. Select **Add**. **Add for Change Tracking** opens.
164
164
@@ -213,7 +213,7 @@ To configure FIM to monitor registry baselines:
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-registry.png" alt-text="Enable FIM on a registry.":::
216
+
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-registry.png" alt-text="Screenshot of enable FIM on a registry.":::
217
217
218
218
### Track changes to Windows files
219
219
@@ -222,7 +222,7 @@ In the example in the following figure,
222
222
**Contoso Web App** resides in the D:\ drive within the **ContosWebApp** folder structure.
223
223
1. Create a custom Windows file entry by providing a name of the setting class, enabling recursion, and specifying the top folder with a wildcard (*) suffix.
224
224
225
-
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-file.png" alt-text="Enable FIM on a file.":::
225
+
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-file.png" alt-text="Screenshot of enable FIM on a file.":::
0 commit comments