Skip to content

Commit 38def3c

Browse files
committed
Fix after PR review
1 parent b21c34a commit 38def3c

6 files changed

+18
-18
lines changed

.openpublishing.redirection.defender-for-cloud.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -712,7 +712,7 @@
712712
},
713713
{
714714
"source_path_from_root": "/articles/defender-for-cloud/file-integrity-monitoring-usage.md",
715-
"redirect_url": "/azure/defender-for-cloud/file-integrity-monitoring-enable-log-analytics#compare-baselines-using-file-integrity-monitoring",
715+
"redirect_url": "/azure/defender-for-cloud/file-integrity-monitoring-enable-log-analytics",
716716
"redirect_document_id": true
717717
},
718718
{

articles/defender-for-cloud/file-integrity-monitoring-enable-ama.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -59,11 +59,11 @@ To enable File Integrity Monitoring (FIM):
5959

6060
1. From Defender for Cloud's sidebar, go to **Workload protections** > **File integrity monitoring**, and select the banner to show the results for machines with Azure Monitor Agent.
6161

62-
:::image type="content" source="media/file-integrity-monitoring-enable-ama/fim-ama-banner.png" alt-text="Screenshot of banner in File integrity monitoring to show the results for machines with Azure Monitor Agent.":::
62+
:::image type="content" source="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-banner.png" alt-text="Screenshot of banner in File integrity monitoring to show the results for machines with Azure Monitor Agent.":::
6363

6464
1. The machines with File Integrity Monitoring enabled are shown.
6565

66-
:::image type="content" source="media/file-integrity-monitoring-enable-ama/fim-ama-results.png" alt-text="Screenshot of File integrity monitoring results for machines with Azure Monitor Agent." lightbox="media/file-integrity-monitoring-enable-ama/fim-ama-results.png":::
66+
:::image type="content" source="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-results.png" alt-text="Screenshot of File integrity monitoring results for machines with Azure Monitor Agent." lightbox="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-results.png":::
6767

6868
You can see the number of changes that were made to the tracked files, and you can select **View changes** to see the changes made to the tracked files on that machine.
6969

@@ -97,7 +97,7 @@ To exclude a machine from File Integrity Monitoring:
9797

9898
- In the list of monitored machines in the FIM results, select the menu (**...**) for the machine and select **Detach data collection rule**.
9999

100-
:::image type="content" source="media/file-integrity-monitoring-enable-ama/fim-ama-detach-rule.png" alt-text="Screenshot of the option to detach a machine from a data collection rule and exclude the machines from File Integrity Monitoring." lightbox="media/file-integrity-monitoring-enable-ama/fim-ama-detach-rule.png":::
100+
:::image type="content" source="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-detach-rule.png" alt-text="Screenshot of the option to detach a machine from a data collection rule and exclude the machines from File Integrity Monitoring." lightbox="media/file-integrity-monitoring-enable-ama/file-integrity-monitoring-azure-monitoring-agent-detach-rule.png":::
101101

102102
The machine moves to the list of unmonitored machines, and file changes aren't tracked for that machine anymore.
103103

articles/defender-for-cloud/file-integrity-monitoring-enable-log-analytics.md

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ FIM is only available from Defender for Cloud's pages in the Azure portal. There
3030

3131
1. From the **Workload protections** dashboard's **Advanced protection** area, select **File integrity monitoring**.
3232

33-
:::image type="content" source="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png" alt-text="Screenshot of opening the File Integrity Monitoring dashboard." lightbox="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png":::
33+
:::image type="content" source="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png" alt-text="Screenshot of screenshot of opening the File Integrity Monitoring dashboard." lightbox="./media/file-integrity-monitoring-overview/open-file-integrity-monitoring.png":::
3434

3535
The following information is provided for each workspace:
3636

@@ -47,14 +47,14 @@ FIM is only available from Defender for Cloud's pages in the Azure portal. There
4747

4848
- ![Enable icon][3] Enable FIM on all machines under the workspace and configure the FIM options. This icon indicates that FIM is not enabled for the workspace.
4949

50-
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-list-fim.png" alt-text="Enabling FIM for a specific workspace.":::
50+
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-list-fim.png" alt-text="Screenshot of enabling FIM for a specific workspace.":::
5151

5252
> [!TIP]
5353
> If there's no enable or upgrade button, and the space is blank, it means that FIM is already enabled on the workspace.
5454
5555
1. Select **ENABLE**. The details of the workspace including the number of Windows and Linux machines under the workspace is shown.
5656

57-
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-fim-status.png" alt-text="FIM workspace details page.":::
57+
:::image type="content" source="./media/file-integrity-monitoring-overview/workspace-fim-status.png" alt-text="Screenshot of FIM workspace details page.":::
5858

5959
The recommended settings for Windows and Linux are also listed. Expand **Windows files**, **Registry**, and **Linux files** to see the full list of recommended items.
6060

@@ -73,7 +73,7 @@ To disable FIM:
7373

7474
1. From the **File Integrity Monitoring dashboard** for a workspace, select **Disable**.
7575

76-
:::image type="content" source="./media/file-integrity-monitoring-overview/disable-file-integrity-monitoring.png" alt-text="Disable file integrity monitoring from the settings page.":::
76+
:::image type="content" source="./media/file-integrity-monitoring-overview/disable-file-integrity-monitoring.png" alt-text="Screenshot of disabling file integrity monitoring from the settings page.":::
7777

7878
1. Select **Remove**.
7979

@@ -83,7 +83,7 @@ To disable FIM:
8383

8484
The **File integrity monitoring** dashboard displays for workspaces where FIM is enabled. The FIM dashboard opens after you enable FIM on a workspace or when you select a workspace in the **file integrity monitoring** window that already has FIM enabled.
8585

86-
:::image type="content" source="./media/file-integrity-monitoring-overview/fim-dashboard.png" alt-text="The FIM dashboard and its various informational panels.":::
86+
:::image type="content" source="./media/file-integrity-monitoring-overview/fim-dashboard.png" alt-text="Screenshot of the FIM dashboard and its various informational panels.":::
8787

8888
The FIM dashboard for a workspace displays the following details:
8989

@@ -94,7 +94,7 @@ The FIM dashboard for a workspace displays the following details:
9494

9595
Select **Filter** at the top of the dashboard to change the time period for which changes are shown.
9696

97-
:::image type="content" source="./media/file-integrity-monitoring-overview/dashboard-filter.png" alt-text="Time period filter for the FIM dashboard.":::
97+
:::image type="content" source="./media/file-integrity-monitoring-overview/dashboard-filter.png" alt-text="Screenshot of time period filter for the FIM dashboard.":::
9898

9999
The **Servers** tab lists the machines reporting to this workspace. For each machine, the dashboard lists:
100100

@@ -103,7 +103,7 @@ The **Servers** tab lists the machines reporting to this workspace. For each mac
103103

104104
When you select a machine, the query appears along with the results that identify the changes made during the selected time period for the machine. You can expand a change for more information.
105105

106-
:::image type="content" source="./media/file-integrity-monitoring-overview/query-machine-changes.png" alt-text="Log Analytics query showing the changes identified by Microsoft Defender for Cloud's file integrity monitoring" lightbox="./media/file-integrity-monitoring-overview/query-machine-changes.png":::
106+
:::image type="content" source="./media/file-integrity-monitoring-overview/query-machine-changes.png" alt-text="Screenshot of log Analytics query showing the changes identified by Microsoft Defender for Cloud's file integrity monitoring." lightbox="./media/file-integrity-monitoring-overview/query-machine-changes.png":::
107107

108108
The **Changes** tab (shown below) lists all changes for the workspace during the selected time period. For each entity that was changed, the dashboard lists the:
109109

@@ -112,17 +112,17 @@ The **Changes** tab (shown below) lists all changes for the workspace during the
112112
- Category of change (modified, added, removed)
113113
- Date and time of change
114114

115-
:::image type="content" source="./media/file-integrity-monitoring-overview/changes-tab.png" alt-text="Microsoft Defender for Cloud's file integrity monitoring changes tab" lightbox="./media/file-integrity-monitoring-overview/changes-tab.png":::
115+
:::image type="content" source="./media/file-integrity-monitoring-overview/changes-tab.png" alt-text="Screenshot of Microsoft Defender for Cloud's file integrity monitoring changes tab." lightbox="./media/file-integrity-monitoring-overview/changes-tab.png":::
116116

117117
**Change details** opens when you enter a change in the search field or select an entity listed under the **Changes** tab.
118118

119-
:::image type="content" source="./media/file-integrity-monitoring-overview/change-details.png" alt-text="Microsoft Defender for Cloud's file integrity monitoring showing the details pane for a change" lightbox="./media/file-integrity-monitoring-overview/change-details.png":::
119+
:::image type="content" source="./media/file-integrity-monitoring-overview/change-details.png" alt-text="Screenshot of Microsoft Defender for Cloud's file integrity monitoring showing the details pane for a change." lightbox="./media/file-integrity-monitoring-overview/change-details.png":::
120120

121121
### Edit monitored entities
122122

123123
1. From the **File Integrity Monitoring dashboard** for a workspace, select **Settings** from the toolbar.
124124

125-
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png" alt-text="Accessing the file integrity monitoring settings for a workspace." lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png":::
125+
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png" alt-text="Screenshot of accessing the file integrity monitoring settings for a workspace." lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-dashboard-settings.png":::
126126

127127
**Workspace Configuration** opens with tabs for each type of element that can be monitored:
128128

@@ -134,7 +134,7 @@ The **Changes** tab (shown below) lists all changes for the workspace during the
134134

135135
Each tab lists the entities that you can edit in that category. For each entity listed, Defender for Cloud identifies whether FIM is enabled (true) or not enabled (false). Edit the entity to enable or disable FIM.
136136

137-
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-workspace-configuration.png" alt-text="Workspace configuration for file integrity monitoring in Microsoft Defender for Cloud.":::
137+
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-workspace-configuration.png" alt-text="Screenshot of workspace configuration for file integrity monitoring in Microsoft Defender for Cloud.":::
138138

139139
1. Select an entry from one of the tabs and edit any of the available fields in the **Edit for Change Tracking** pane. Options include:
140140

@@ -158,7 +158,7 @@ The **Changes** tab (shown below) lists all changes for the workspace during the
158158

159159
In this example, we selected **Linux Files**.
160160

161-
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png" alt-text="Adding an element to monitor in Microsoft Defender for Cloud's file integrity monitoring" lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png":::
161+
:::image type="content" source="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png" alt-text="Screenshot of adding an element to monitor in Microsoft Defender for Cloud's file integrity monitoring." lightbox="./media/file-integrity-monitoring-overview/file-integrity-monitoring-add-element.png":::
162162

163163
1. Select **Add**. **Add for Change Tracking** opens.
164164

@@ -213,7 +213,7 @@ To configure FIM to monitor registry baselines:
213213
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
214214
```
215215
216-
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-registry.png" alt-text="Enable FIM on a registry.":::
216+
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-registry.png" alt-text="Screenshot of enable FIM on a registry.":::
217217
218218
### Track changes to Windows files
219219
@@ -222,7 +222,7 @@ In the example in the following figure,
222222
**Contoso Web App** resides in the D:\ drive within the **ContosWebApp** folder structure.
223223
1. Create a custom Windows file entry by providing a name of the setting class, enabling recursion, and specifying the top folder with a wildcard (*) suffix.
224224
225-
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-file.png" alt-text="Enable FIM on a file.":::
225+
:::image type="content" source="./media/file-integrity-monitoring-enable-log-analytics/baselines-add-file.png" alt-text="Screenshot of enable FIM on a file.":::
226226
227227
### Retrieve change data
228228
Loading
Loading
Loading

0 commit comments

Comments
 (0)