Skip to content

Commit 58f582c

Browse files
authored
Merge pull request #203453 from batamig/sensor-health
Cloud release post 22.2.3: Sensor health - sanity
2 parents 1f00ebc + 740e5f3 commit 58f582c

15 files changed

+128
-24
lines changed

articles/defender-for-iot/organizations/TOC.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -215,8 +215,6 @@
215215
href: how-to-troubleshoot-the-sensor-and-on-premises-management-console.md
216216
- name: Reference
217217
items:
218-
- name: Alert reference
219-
href: alert-engine-messages.md
220218
- name: OT monitoring appliances
221219
items:
222220
- name: Overview
@@ -255,6 +253,10 @@
255253
href: appliance-catalog/hpe-edgeline-el300.md
256254
- name: Neousys Nuvo-500LP (SMB rugged)
257255
href: appliance-catalog/neousys-nuvo-5006lp.md
256+
- name: Alert reference
257+
href: alert-engine-messages.md
258+
- name: Sensor health message reference
259+
href: sensor-health-messages.md
258260
- name: Defender for IoT APIs
259261
href: references-work-with-defender-for-iot-apis.md
260262
- name: Defender for IoT CLI commands

articles/defender-for-iot/organizations/how-to-manage-sensors-on-the-cloud.md

Lines changed: 65 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Manage sensors with Defender for IoT in the Azure portal
3-
description: Learn how to view, and manage sensors with Defender for IoT in the Azure portal.
4-
ms.date: 06/02/2022
3+
description: Learn how to onboard, view, and manage sensors with Defender for IoT in the Azure portal.
4+
ms.date: 08/08/2022
55
ms.topic: how-to
66
---
77

@@ -11,10 +11,10 @@ This article describes how to view and manage sensors with [Defender for IoT in
1111

1212
## Purchase sensors or download software for sensors
1313

14-
This procedure describes how to use the Azure portal to contact vendors for pre-configured appliances, or how to download software for you to install on your own appliances.
14+
This procedure describes how to use the Azure portal to contact vendors for pre-configured appliances, or how to download software for you to install on your own appliances.
1515

1616
1. In the Azure portal, go to **Defender for IoT** > **Getting started** > **Sensor**.
17-
17+
1818
1. Do one of the following:
1919

2020
- To buy a pre-configured appliance, select **Contact** under **Buy preconfigured appliance**. This opens an email to [[email protected]](mailto:[email protected]) with a template request for Defender for IoT appliances. For more information, see [Pre-configured physical appliances for OT monitoring](ot-pre-configured-appliances.md).
@@ -29,15 +29,15 @@ This procedure describes how to use the Azure portal to contact vendors for pre-
2929

3030
1. Install your software. For more information, see [Defender for IoT installation](how-to-install-software.md).
3131

32-
3332
## Onboard sensors
3433

3534
Onboard a sensor by registering it with Microsoft Defender for IoT. For OT sensors, you'll also need to download a sensor activation file.
3635

3736
Select one of the following tabs, depending on the type of network you're working with.
37+
3838
# [OT sensors](#tab/ot)
3939

40-
**Prerequisites**: Make sure that you've set up your sensor and configured your SPAN port or TAP.
40+
**Prerequisites**: Make sure that you've set up your sensor and configured your SPAN port or TAP.
4141

4242
For more information, see [Activate and set up your sensor](how-to-activate-and-set-up-your-sensor.md) and [Defender for IoT installation](how-to-install-software.md), or our [Tutorial: Get started with Microsoft Defender for IoT for OT security](tutorial-onboarding.md).
4343

@@ -104,22 +104,28 @@ Make the downloaded activation file accessible to the sensor console admin so th
104104

105105
## Sensor management options from the Azure portal
106106

107-
Sensors that you've on-boarded to Defender for IoT are listed on the Defender for IoT **Sites and sensors** page. From the **Sites and sensors** page, do any of the following:
107+
Sensors that you've on-boarded to Defender for IoT are listed on the Defender for IoT **Sites and sensors** page. Select a specific sensor name to drill down to more details for that sensor.
108108

109-
|Task |Steps |
110-
|---------|---------|
111-
| **Push threat intelligence updates** | Select your sensor in the grid > **Push Threat Intelligence update**. For more information, see [Threat intelligence research and packages](how-to-work-with-threat-intelligence-packages.md). |
112-
|**Prepare an OT sensor to update to software version 22.x or higher** | Select your sensor in the grid > **Prepare to update to 22.X**. For more information, see: <br><br>-[Reactivate a sensor for upgrades to version 22.x from a legacy version](how-to-manage-sensors-on-the-cloud.md#reactivate-an-ot-sensor-for-upgrades-to-version-22x-from-a-legacy-version)<br>- [Update Defender for IoT OT monitoring software](update-ot-software.md#download-and-apply-a-new-activation-file) |
113-
|**Export sensor data** |Select **Export** at the top of the page. A CSV file is downloaded with details about all sensors listed. |
114-
|**Download an activation file** | From the **...** options menu at the right of a sensor row. For more information, see [Reactivate a sensor](#reactivate-a-sensor). |
115-
|**Edit a sensor zone** | From the **...** options menu at the right of a sensor row, select **Edit**. From the **Zone** menu, select a zone, or **Create new zone**. Select **Submit** to save your changes. |
116-
|**Edit automatic threat intelligence updates** | From the **...** options menu at the right of a sensor row, select **Edit**. Toggle the **Automatic Threat Intelligence Updates (Preview)** option on or off as needed. Select **Submit** to save your changes. |
117-
|**Delete a sensor** | Delete sensors only if you're no longer working with them. From the **...** options menu at the right of a sensor row, select **Delete sensor**. |
109+
Use the options on the **Sites and sensor** page and a sensor details page to do any of the following tasks. If you're on the **Sites and sensors** page, select multiple sensors to apply your actions in bulk using toolbar options. For individual sensors, use the **Sites and sensors** toolbar options, the **...** options menu at the right of a sensor row, or the options on a sensor details page.
118110

119-
120-
## Reactivate a sensor
121-
122-
You may need to reactivate your sensor because you want to:
111+
|Task |Description |
112+
|---------|---------|
113+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-threat-intelligence.png" border="false"::: **Push threat intelligence updates** | OT sensors only. <br><br>Available for bulk actions from the **Sites and sensors** toolbar, for individual sensors from the **...** options menu, or from a sensor details page. <br><br>For more information, see [Threat intelligence research and packages](how-to-work-with-threat-intelligence-packages.md). |
114+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-prepare-to-update.png" border="false"::: **Prepare an OT sensor to update to software version 22.x or higher** | Individual, OT sensors only. <br><br>Available from the **Sites and sensors** toolbar, the **...** options menu, or a sensor details page. <br><br>For more information, see: <br>- [Reactivate a sensor for upgrades to version 22.x from a legacy version](how-to-manage-sensors-on-the-cloud.md#reactivate-an-ot-sensor-for-upgrades-to-version-22x-from-a-legacy-version)<br>- [Update Defender for IoT OT monitoring software](update-ot-software.md#download-and-apply-a-new-activation-file) |
115+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-recover.png" border="false"::: **Recover a password** | Individual, OT sensors only. <br><br>Available from the **...** options menu or a sensor details page. Enter the secret identifier obtained on the sensor's sign-in screen. |
116+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-export.png" border="false"::: **Export sensor data** | Available from the **Sites and sensors** toolbar only, to download a CSV file with details about all the sensors listed. |
117+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-export.png" border="false"::: **Download an activation file** | Individual, OT sensors only. <br><br>Available from the **...** options menu or a sensor details page. |
118+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-edit.png" border="false"::: **Edit a sensor zone** | For individual sensors only, from the **...** options menu or a sensor details page. <br><br>Select **Edit**, and then elect a new zone from the **Zone** menu or select **Create new zone**. Select **Submit** to save your changes. |
119+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-edit.png" border="false"::: **Create an activation command** | Individual, Enterprise IoT sensors only. <br><br>Available from the **...** options menu or a sensor details page. Select **Edit** and then select **Create activation command**. <br><br>For more information, see [Install an Enterprise IoT sensor](tutorial-getting-started-eiot-sensor.md#install-the-sensor). |
120+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-edit.png" border="false"::: **Edit automatic threat intelligence updates** | Individual, OT sensors only. <br><br>Available from the **...** options menu or a sensor details page. <br><br>Select **Edit** and then toggle the **Automatic Threat Intelligence Updates (Preview)** option on or off as needed. Select **Submit** to save your changes. |
121+
|:::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-delete.png" border="false"::: **Delete a sensor** | For individual sensors only, from the **...** options menu or a sensor details page. |
122+
| **Download SNMP MIB file** | Available from the **Sites and sensors** toolbar **More actions** menu. <br><br>For more information, see [Set up SNMP MIB monitoring](how-to-set-up-snmp-mib-monitoring.md).|
123+
| **Recover an on-premises management console password** | Available from the **Sites and sensors** toolbar **More actions** menu. <br><br>For more information, see [Manage the on-premises management console](how-to-manage-the-on-premises-management-console.md). |
124+
| :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/icon-diagnostics.png" border="false"::: **Send diagnostic files to support** | Individual, locally managed OT sensors only. <br><br>Available from the **...** options menu. <br><br>For more information, see [Upload a diagnostics log for support (Public preview)](#upload-a-diagnostics-log-for-support-public-preview).|
125+
126+
## Reactivate an OT sensor
127+
128+
You may need to reactivate an OT sensor because you want to:
123129

124130
- **Work in cloud-connected mode instead of locally managed mode**: After reactivation, existing sensor detections are displayed in the sensor console, and newly detected alert information is delivered through Defender for IoT in the Azure portal. This information can be shared with other Azure services, such as Microsoft Sentinel.
125131

@@ -143,6 +149,45 @@ Make sure that you've started with the relevant updates steps for this update. F
143149
> After upgrading to version 22.1.x, the new upgrade log can be found at the following path, accessed via SSH and the *cyberx_host* user: `/opt/sensor/logs/legacy-upgrade.log`.
144150
>
145151
152+
## Understand sensor health (Public preview)
153+
154+
This procedure describes how to view sensor health data from the Azure portal. Sensor health includes data such as whether traffic is stable, the sensor is overloaded, notifications about sensor software versions, and more.
155+
156+
**To view overall sensor health**:
157+
158+
1. From Defender for IoT in the Azure portal, select **Sites and sensors** and then check the overall health score in the widget above the grid. For example:
159+
160+
:::image type="content" source="media/how-to-manage-sensors-on-the-cloud/sensor-widgets.png" alt-text="Screenshot showing the sensor health widgets." lightbox="media/how-to-manage-sensors-on-the-cloud/sensor-widgets.png":::
161+
162+
- **Unhealthy** indicates one of the following scenarios:
163+
164+
- Sensor traffic to Azure isn't stable
165+
- Sensor fails regular sanity tests
166+
- No traffic detected by the sensor
167+
- Sensor software version is no longer supported
168+
- A [remote sensor upgrade from the Azure portal](update-ot-software.md#update-your-sensors) fails
169+
170+
For more information, see our [Sensor health message reference](sensor-health-messages.md).
171+
172+
- **Updatable** means that the sensor has an older version, and there are software updates available to install
173+
- **Unsupported** means that the sensor has a software version install that is no longer supported.
174+
175+
1. To check on specific sensor issues, filter the grid by sensor health, and select one or more issues to verify. For example:
176+
177+
:::image type="content" source="media/how-to-manage-sensors-on-the-cloud/sensor-health-filter.png" alt-text="Screenshot of the sensor health filter." lightbox="media/how-to-manage-sensors-on-the-cloud/sensor-health-filter.png":::
178+
179+
1. Expand the filtered sites and sensors now displayed in the grid, and use the **Sensor health** column to learn more at a high level.
180+
181+
1. To drill down further and understand recommended actions, select a sensor name to open the sensor details page.
182+
183+
For example:
184+
185+
:::image type="content" source="media/how-to-manage-sensors-on-the-cloud/sensor-details-health.png" alt-text="Screenshot of the sensor details page showing health information." lightbox="media/how-to-manage-sensors-on-the-cloud/sensor-details-health.png":::
186+
187+
On the sensor details **Overview** page, expand the **Health** section and any messages listed there to learn more. The **Recommendation** column on the right lists recommended actions for handling the health issue.
188+
189+
For more information, see our [Sensor health message reference](sensor-health-messages.md).
190+
146191
## Upload a diagnostics log for support (Public preview)
147192

148193
If you need to open a support ticket for a locally managed sensor, upload a diagnostics log to the Azure portal for the support team.
@@ -161,7 +206,6 @@ If you need to open a support ticket for a locally managed sensor, upload a diag
161206

162207
:::image type="content" source="media/how-to-manage-sensors-on-the-cloud/upload-diagnostics-log.png" alt-text="Screenshot of the send diagnostic files to support option." lightbox="media/how-to-manage-sensors-on-the-cloud/upload-diagnostics-log.png":::
163208

164-
165209
## Next steps
166210

167211
[View and manage alerts on the Defender for IoT portal (Preview)](how-to-manage-cloud-alerts.md)
576 Bytes
Loading
1.5 KB
Loading
804 Bytes
Loading
470 Bytes
Loading
864 Bytes
Loading
633 Bytes
Loading
711 Bytes
Loading
177 KB
Loading

0 commit comments

Comments
 (0)