Skip to content

Commit 431acf5

Browse files
authored
Merge pull request #202094 from MicrosoftDocs/main
4 P.M. Sunday Publish, 6/19/22
2 parents c944420 + d1ed174 commit 431acf5

File tree

12 files changed

+113
-74
lines changed

12 files changed

+113
-74
lines changed

articles/azure-monitor/alerts/alerts-common-schema-definitions.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -276,18 +276,18 @@ Any alert instance describes the resource that was affected and the cause of the
276276
]
277277
]
278278
}
279+
],
280+
"dataSources": [
281+
{
282+
"resourceId": "/subscriptions/a5ea55e2-7482-49ba-90b3-60e7496dd873/resourcegroups/test/providers/microsoft.operationalinsights/workspaces/test",
283+
"tables": [
284+
"Heartbeat"
285+
]
286+
}
279287
]
280288
},
281-
"dataSources": [
282-
{
283-
"resourceId": "/subscriptions/a5ea55e2-7482-49ba-90b3-60e7496dd873/resourcegroups/test/providers/microsoft.operationalinsights/workspaces/test",
284-
"tables": [
285-
"Heartbeat"
286-
]
287-
}
288-
],
289-
"IncludedSearchResults": "True",
290-
"AlertType": "Metric measurement"
289+
"IncludedSearchResults": "True",
290+
"AlertType": "Metric measurement"
291291
}
292292
}
293293
```

articles/defender-for-cloud/includes/defender-for-containers-enable-plan-aks.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: bmansheim
3-
ms.author: benmansheim
2+
author: ElazarK
3+
ms.author: elkrieger
44
ms.service: defender-for-cloud
55
ms.topic: include
6-
ms.date: 05/26/2022
6+
ms.date: 06/19/2022
77
---
88

99
## Enable the plan
@@ -171,10 +171,10 @@ Request body parameters:
171171
1. To verify that the profile was successfully added, run the following command on your machine with the `kubeconfig` file pointed to your cluster:
172172
173173
```console
174-
kubectl get pods -n azuredefender
174+
kubectl get pods -n kube-system
175175
```
176176
177-
When the profile is added, you should see a pod called `azuredefender-XXXXX` in `Running` state. It might take a few minutes for pods to be added.
177+
When the profile is added, you should see a pods called `azuredefender-XXXXX` in `Running` state. It might take a few minutes for pods to be added.
178178
179179
### [**Resource Manager**](#tab/aks-deploy-arm)
180180

articles/defender-for-cloud/permissions.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ The following table displays roles and allowed actions in Defender for Cloud.
3030
| Edit security policy | - || - |||
3131
| Enable / disable Microsoft Defender plans | - || - |||
3232
| Dismiss alerts | - || - |||
33-
| Apply security recommendations for a resource</br> (and use [Fix](implement-security-recommendations.md#fix-button)) | - | ||||
33+
| Apply security recommendations for a resource</br> (and use [Fix](implement-security-recommendations.md#fix-button)) | - | - ||||
3434
| View alerts and recommendations ||||||
3535

3636

articles/defender-for-iot/organizations/appliance-catalog/hpe-edgeline-el300.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ The following image shows a view of the back panel of the HPE Edgeline EL300.
3434
|CPU|Intel Core i7-8650U (1.9GHz/4-core/15W)|
3535
|Chipset|Intel® Q170 Platform Controller Hub|
3636
|Memory|8 GB DDR4 2133 MHz Wide Temperature SODIMM|
37-
|Storage|128 GB 3ME3 Wide Temperature mSATA SSD|
37+
|Storage|256-GB SATA 6G Read Intensive M.2 2242 3 year warranty wide temperature SSD|
3838
|Network controller|6x Gigabit Ethernet ports by Intel® I219|
3939
|Device access|4 USBs: Two fronts; two rears; 1 internal|
4040
|Power Adapter|250V/10A|

articles/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl20-plus-enterprise.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -144,6 +144,10 @@ This procedure describes how to update the HPE BIOS configuration for your OT de
144144

145145
1. In the **Create Array** form, select all the options. Three options are available for the **Enterprise** appliance.
146146

147+
> [!NOTE]
148+
> For **Data-at-Rest** encryption, see the HPE guidance for activating RAID Secure Encryption or using Self-Encrypting-Drives (SED).
149+
>
150+
147151
### Install Defender for IoT software on the HPE ProLiant DL20 or HPE ProLiant DL20 Plus
148152

149153
This procedure describes how to install Defender for IoT software on the HPE ProLiant DL20 or HPE ProLiant DL20 Plus.

articles/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl360.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ The following image shows a view of the HPE ProLiant Dl360 back panel:
4747
|**Power** |Two HPE 500-W flex slot platinum hot plug low halogen power supply kit
4848
|**Rack support** | HPE 1U Gen10 SFF easy install rail kit |
4949

50+
5051
## HPE DL360 BOM
5152

5253
|PN |Description |Quantity|
@@ -136,6 +137,9 @@ This procedure describes how to update the HPE BIOS configuration for your OT se
136137

137138
1. In the **Create Array** form, select all the options.
138139

140+
> [!NOTE]
141+
> For **Data-at-Rest** encryption, see the HPE guidance for activating RAID Secure Encryption or using Self-Encrypting-Drives (SED).
142+
>
139143
140144
### Install iLO remotely from a virtual drive
141145

articles/defender-for-iot/organizations/how-to-create-and-manage-users.md

Lines changed: 43 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -134,18 +134,54 @@ To update sign-out counting periods, adjust the `= <number>` value to the requir
134134

135135
## Track user activity
136136

137-
You can track user activity in the event timeline on each sensor. The timeline displays the event or affected device, and the time and date that the user carried out the activity.
137+
Track user activity on a sensor's event timeline, or by viewing audit logs generated on an on-premises management console.
138138

139-
**To view user activity**:
139+
- **The timeline** displays the event or affected device, and the time and date that the user carried out the activity.
140140

141-
1. Select **Event Timeline** from the sensor side menu.
141+
- **Audit logs** record key activity data at the time of occurrence. Use audit logs generated on the on-premises management console to understand which changes were made, when, and by whom.
142142

143-
1. Verify that **User Operations** filter is set to **Show**.
143+
### View user activity on the sensor's Event Timeline
144144

145-
:::image type="content" source="media/how-to-create-and-manage-users/track-user-activity.png" alt-text="Screenshot of the Event timeline showing a user that signed in to Defender for IoT.":::
145+
Select **Event Timeline** from the sensor side menu. If needed, verify that **User Operations** filter is set to **Show**.
146146

147-
1. Use the filters or Ctrl F option to find the information of interest to you.
147+
For example:
148148

149+
:::image type="content" source="media/how-to-create-and-manage-users/track-user-activity.png" alt-text="Screenshot of the Event timeline showing a user that signed in to Defender for IoT.":::
150+
151+
Use the filters or search using CTRL+F to find the information of interest to you.
152+
153+
### View audit log data on the on-premises management console
154+
155+
In the on-premises management console, select **System Settings > System Statistics**, and then select **Audit log**.
156+
157+
The dialog displays data from the currently active audit log. For example:
158+
159+
For example:
160+
161+
:::image type="content" source="media/how-to-create-and-manage-users/view-audit-logs.png" alt-text="Screenshot of the on-premises management console showing audit logs." lightbox="media/how-to-create-and-manage-users/view-audit-logs.png":::
162+
163+
New audit logs are generated at every 10 MB. One previous log is stored in addition to the current active log file.
164+
165+
Audit logs include the following data:
166+
167+
| Action | Information logged |
168+
|--|--|
169+
| **Learn, and remediation of alerts** | Alert ID |
170+
| **Password changes** | User, User ID |
171+
| **Login** | User |
172+
| **User creation** | User, User role |
173+
| **Password reset** | User name |
174+
| **Exclusion rules-Creation**| Rule summary |
175+
| **Exclusion rules-Editing**| Rule ID, Rule Summary |
176+
| **Exclusion rules-Deletion** | Rule ID |
177+
| **Management Console Upgrade** | The upgrade file used |
178+
| **Sensor upgrade retry** | Sensor ID |
179+
| **Uploaded TI package** | No additional information recorded. |
180+
181+
182+
> [!TIP]
183+
> You may also want to export your audit logs to send them to the support team for extra troubleshooting. For more information, see [Export audit logs for troubleshooting](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md#export-audit-logs-for-troubleshooting)
184+
>
149185
150186
## Change a user's password
151187

@@ -232,6 +268,7 @@ You can recover the password for the on-premises management console or the senso
232268
233269
1. Select **Next**, and your user, and a system-generated password for your management console will then appear.
234270

271+
235272
## Next steps
236273

237274
- [Activate and set up your sensor](how-to-activate-and-set-up-your-sensor.md)

articles/defender-for-iot/organizations/how-to-troubleshoot-the-sensor-and-on-premises-management-console.md

Lines changed: 22 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Troubleshoot the sensor and on-premises management console
33
description: Troubleshoot your sensor and on-premises management console to eliminate any problems you might be having.
4-
ms.date: 05/22/2022
4+
ms.date: 06/15/2022
55
ms.topic: article
66
---
77
# Troubleshoot the sensor and on-premises management console
@@ -262,13 +262,14 @@ All allowlists, policies, and configuration settings are cleared, and the sensor
262262

263263

264264
## Troubleshoot an on-premises management console
265-
### Investigate a lack of expected alerts on the management console
266265

267-
If an expected alert is not shown in the **Alerts** window, verify the following:
266+
### Investigate a lack of expected alerts
267+
268+
If you don't see an expected alert on the on-premises **Alerts** page, do the following to troubleshoot:
268269

269-
- Check if the same alert already appears in the **Alerts** window as a reaction to a different security instance. If yes, and this alert has not been handled yet, a new alert is not shown.
270+
- Verify whether the alert is already listed as a reaction to a different security instance. If it has, and that alert hasn't yet been handled, a new alert isn't shown elsewhere.
270271

271-
- Verify that you did not exclude this alert by using the **Alert Exclusion** rules in the on-premises management console.
272+
- Verify that the alert isn't being excluded by **Alert Exclusion** rules. For more information, see [Create alert exclusion rules](how-to-work-with-alerts-on-premises-management-console.md#create-alert-exclusion-rules).
272273

273274
### Tweak the Quality of Service (QoS)
274275

@@ -310,39 +311,33 @@ To limit the number of alerts, use the `notifications.max_number_to_report` prop
310311

311312
1. Save the changes. No restart is required.
312313

314+
### Export audit logs for troubleshooting
313315

316+
Audit logs record key activity data at the time of occurrence. Use audit logs generated on the on-premises management console to understand which changes were made, when, and by whom.
314317

315-
### Export audit logs from the management console
318+
You may also want to export your audit logs to send them to the support team for extra troubleshooting.
319+
320+
> [!NOTE]
321+
> New audit logs are generated at every 10 MB. One previous log is stored in addition to the current active log file.
322+
>
316323
317-
Audit logs record key information at the time of occurrence. Audit logs are useful when you are trying to figure out what changes were made, and by who. Audit logs can be exported in the management console, and contain the following information:
324+
**To export audit log data**:
318325

319-
| Action | Information logged |
320-
|--|--|
321-
| **Learn, and remediation of alerts** | Alert ID |
322-
| **Password changes** | User, User ID |
323-
| **Login** | User |
324-
| **User creation** | User, User role |
325-
| **Password reset** | User name |
326-
| **Exclusion rules-Creation**| Rule summary |
327-
| **Exclusion rules-Editing**| Rule ID, Rule Summary |
328-
| **Exclusion rules-Deletion** | Rule ID |
329-
| **Management Console Upgrade** | The upgrade file used |
330-
| **Sensor upgrade retry** | Sensor ID |
331-
| **Uploaded TI package** | No additional information recorded. |
326+
1. In the on-premises management console, select **System Settings > Export**.
332327

333-
**To export the audit log**:
328+
1. In the **Export Troubleshooting Information** dialog:
334329

335-
1. In the management console, in the left pane, select **System Settings**.
330+
1. In the **File Name** field, enter a meaningful name for the exported log. The default filename uses the current date, such as **13:10-June-14-2022.tar.gz**.
336331

337-
1. Select **Export**.
332+
1. Select **Audit Logs**.
338333

339-
1. In the File Name field, enter the file name that you want to use for the exported log. If no name is entered, the default file name will be the current date.
334+
1. Select **Export**.
340335

341-
1. Select **Audit Logs**.
336+
The file is exported and is linked from the **Archived Files** list at the bottom of the **Export Troubleshooting Information** dialog. Select the link to download the file.
342337

343-
1. Select **Export**.
338+
1. Exported audit logs are encrypted for your security, and require a password to open. In the **Archived Files** list, select the :::image type="icon" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/eye-icon.png" border="false"::: button for your exported logs to view its password. If you're forwarding the audit logs to the support team, make sure to send the password to support separately from the exported logs.
344339

345-
The exported log is added to the **Archived Logs** list. Select the :::image type="icon" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/eye-icon.png" border="false"::: button to view the OTP. Send the OTP string to the support team in a separate message from the exported logs. The support team will be able to extract exported logs only by using the unique OTP that's used to encrypt the logs.
340+
For more information, see [View audit log data on the on-premises management console](how-to-create-and-manage-users.md#view-audit-log-data-on-the-on-premises-management-console).
346341

347342
## Next steps
348343

680 KB
Loading

articles/postgresql/flexible-server/concepts-high-availability.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -169,15 +169,15 @@ Flexible servers that are configured with high availability, log data is replica
169169
2. If you just want to restore an object, you can then export the object from the restored database server and import it to your production database server.
170170
3. If you want to clone your database server for testing and development purposes, or you want to restore for any other purposes, you can perform point-in-time restore.
171171

172-
## Zone redundant high availability - features
172+
## High availability - features
173173

174174
* Standby replica will be deployed in an exact VM configuration same as the primary server, including vCores, storage, network settings (VNET, Firewall), etc.
175175

176176
* You can add high availability for an existing database server.
177177

178178
* You can remove standby replica by disabling high availability.
179179

180-
* You can only choose your availability zone for your primary database server. Standby zone is auto-selected.
180+
* For zone-redundant HA, you can choose your availability zones for your primary and standby database servers.
181181

182182
* Operations such as stop, start, and restart are performed on both primary and standby database servers at the same time.
183183

@@ -191,11 +191,11 @@ Flexible servers that are configured with high availability, log data is replica
191191

192192
* Periodic maintenance activities such as minor version upgrades happen at the standby first and the service is failed over to reduce downtime.
193193

194-
## Zone redundant high availability - limitations
194+
## High availability - limitations
195195

196196
* High availability is not supported with burstable compute tier.
197197
* High availability is supported only in regions where multiple zones are available.
198-
* Due to synchronous replication to another availability zone, applications can experience elevated write and commit latency.
198+
* Due to synchronous replication to the standby server, especially with zone-redundant HA, applications can experience elevated write and commit latency.
199199

200200
* Standby replica cannot be used for read queries.
201201

@@ -212,7 +212,7 @@ Flexible servers that are configured with high availability, log data is replica
212212

213213
* If logical decoding or logical replication is configured with a HA configured flexible server, in the event of a failover to the standby server, the logical replication slots are not copied over to the standby server.
214214

215-
## Availability without high availability
215+
## Availability for non-HA servers
216216

217217
For Flexible servers configured **without** high availability, the service still provides built-in availability, storage redundancy and resiliency to help to recover from any planned or unplanned downtime events.
218218

@@ -257,7 +257,7 @@ Here are some failure scenarios that require user action to recover:
257257

258258
* **Can I choose the availability zones for my primary and standby servers?** <br>
259259
If you choose same zone HA, then you can only choose the primary server. If you choose zone redundant HA, then you can choose both primary and standby AZs.
260-
260+
261261
* **Is zone redundant HA available in all regions?** <br>
262262
Zone-redundant HA is available in regions that support multiple AZs in the region. For the latest region support, please see [this documentation](overview.md#azure-regions). We are continuously adding more regions and enabling multiple AZs. Note that same-zone HA is available in all regions.
263263

0 commit comments

Comments
 (0)