Skip to content

Commit 4b097f4

Browse files
committed
Update how-to-configure-with-sentinel.md
1 parent e4c1e45 commit 4b097f4

File tree

1 file changed

+8
-6
lines changed

1 file changed

+8
-6
lines changed

articles/defender-for-iot/organizations/how-to-configure-with-sentinel.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,14 +2,14 @@
22
title: Configure Azure Sentinel with Defender for IoT for organizations
33
description: Explains how to configure Azure Sentinel to receive data from your Defender for IoT solution.
44
ms.topic: how-to
5-
ms.date: 06/14/2021
5+
ms.date: 11/04/2021
66
---
77

88
# Connect your data from Defender for IoT for organizations to Azure Sentinel (Public preview)
99

1010
Use the Defender for IoT connector to stream all your Defender for IoT events into Azure Sentinel.
1111

12-
This integration enables organizations to quickly detect multistage attacks that often cross IT and OT boundaries. Additionally, Defender for IoT’s integration with Azure Sentinel's security orchestration, automation, and response (SOAR) capabilities enables automated response and prevention using built-in OT-optimized playbooks.
12+
This integration enables organizations to quickly detect multistage attacks that often cross IT and OT boundaries. Additionally, Defender for IoT’s integration with Azure Sentinel's security orchestration, automation, and response (SOAR) capabilities enables automated response and prevention using built-in OT-optimized playbooks.
1313

1414
## Prerequisites
1515

@@ -24,12 +24,14 @@ This integration enables organizations to quickly detect multistage attacks that
2424
1. From the bottom of the right pane, click **Open connector page**.
2525

2626
1. Click **Connect**, next to each IoT Hub subscription whose alerts and device alerts you want to stream into Azure Sentinel.
27-
- You will receive an error message if Defender for IoT is not enabled on at least one IoT Hub within a subscription. Enable Defender for IoT within the IoT Hub to remove the error.
2827

29-
1. You can decide whether you want the alerts from Defender for IoT to automatically generate incidents in Azure Sentinel. Under **Create incidents**, select **Enable** to enable the default analytics rule to automatically create incidents from the generated alerts. This rule can be changed or edited under **Analytics** > **Active rules**.
28+
> [!NOTE]
29+
> You will receive an error message if Defender for IoT is not enabled on at least one IoT Hub within that subscription. Enable Defender for IoT within the IoT Hub to remove the error.
30+
31+
1. You can decide whether you want the alerts from Defender for IoT to automatically generate incidents in Azure Sentinel. Under **Create incidents**, select **Enable** to enable the default analytics rule to automatically create incidents from the generated alerts. This rule can be changed or edited under **Analytics** > **Active rules**.
3032

3133
> [!NOTE]
32-
> It can take 10 seconds or more for the **Subscription** list to refresh after making connection changes.
34+
> It can take 10 seconds or more for the **Subscription** list to refresh after making connection changes.
3335
3436
## Log Analytics alert view
3537

@@ -51,4 +53,4 @@ After connecting a **Subscription**, the hub data is available in Azure Sentinel
5153

5254
In this document, you learned how to connect Defender for IoT to Azure Sentinel. To learn more about threat detection and security data access, see the following articles:
5355

54-
- Learn how to use Azure Sentinel to [Quickstart: Get started with Azure Sentinel](../../sentinel/get-visibility.md).
56+
- Learn how to use Azure Sentinel to [Quickstart: Get started with Azure Sentinel](../../sentinel/get-visibility.md)

0 commit comments

Comments
 (0)