You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-troubleshoot-the-sensor-and-on-premises-management-console.md
+72-39Lines changed: 72 additions & 39 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,40 +1,40 @@
1
1
---
2
2
title: Troubleshoot the sensor and on-premises management console
3
3
description: Troubleshoot your sensor and on-premises management console to eliminate any problems you might be having.
4
-
ms.date: 05/10/2021
4
+
ms.date: 10/17/2021
5
5
ms.topic: article
6
6
---
7
7
# Troubleshoot the sensor and on-premises management console
8
8
9
9
This article describes basic troubleshooting tools for the sensor and the on-premises management console. In addition to the items described here, you can check the health of your system in the following ways:
10
10
11
-
**Alerts**: An alert is created when the sensor interface that monitors the traffic is down.
11
+
**Alerts**: An alert is created when the sensor interface that monitors the traffic is down.
12
12
13
-
**SNMP**: Sensor health is monitored through SNMP. Azure Defender for IoT responds to SNMP queries sent from an authorized monitoring server.
13
+
**SNMP**: Sensor health is monitored through SNMP. Azure Defender for IoT responds to SNMP queries sent from an authorized monitoring server.
14
14
15
15
**System notifications**: When a management console controls the sensor, you can forward alerts about failed sensor backups and disconnected sensors.
16
16
17
17
## Sensor troubleshooting tools
18
18
19
-
### Investigate password failure at initial sign-in
19
+
### Investigate password failure at initial signin
20
20
21
21
When signing into a preconfigured Arrow sensor for the first time, you'll need to perform password recovery.
22
22
23
-
To recover your password:
23
+
**To recover your password**:
24
24
25
-
1. On the Defender for IoT sign-in screen, select **Password recovery**. The **Password recovery** screen opens.
25
+
1. On the Defender for IoT signin screen, select **Password recovery**. The **Password recovery** screen opens.
26
26
27
27
1. Select either **CyberX** or **Support**, and copy the unique identifier.
28
28
29
29
1. Navigate to the Azure portal and select **Sites and Sensors**.
30
30
31
31
1. Select the **More Actions** drop down menu and select **Recover on-premises management console password**.
32
32
33
-
:::image type="content" source="media/how-to-create-and-manage-users/recover-password.png" alt-text="Select your sensor and select the recover on-premises management console password option.":::
33
+
:::image type="content" source="media/how-to-create-and-manage-users/recover-password.png" alt-text=" Screenshot of the recover on-premises management console password option.":::
34
34
35
35
1. Enter the unique identifier that you received on the **Password recovery** screen and select **Recover**. The `password_recovery.zip` file is downloaded.
36
36
37
-
:::image type="content" source="media/how-to-create-and-manage-users/enter-identifier.png" alt-text="Enter the unique identifier and then select recover.":::
37
+
:::image type="content" source="media/how-to-create-and-manage-users/enter-identifier.png" alt-text="Screenshot of the enter the unique identifier and then select recover.":::
38
38
39
39
> [!NOTE]
40
40
> Don't alter the password recovery file. It's a signed file and won't work if you tamper with it.
@@ -53,75 +53,74 @@ To recover your password:
53
53
An indicator appears at the top of the console when the sensor recognizes that there's no traffic on one of the configured ports. This indicator is visible to all users.
54
54
55
55
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/no-traffic-detected.png" alt-text="Screenshot of the alert that no traffic was detected.":::
56
-
56
+
57
57
When this message appears, you can investigate where there's no traffic. Make sure the span cable is connected and there was no change in the span architecture.
58
58
59
59
For support and troubleshooting information, contact [Microsoft Support](https://support.serviceshub.microsoft.com/supportforbusiness/create?sapId=82c88f35-1b8e-f274-ec11-c6efdd6dd099).
60
60
61
-
### Check system performance
61
+
### Check system performance
62
62
63
63
When a new sensor is deployed or, for example, the sensor is working slowly or not showing any alerts, you can check system performance.
64
64
65
-
To check system performance:
65
+
**To check system performance**:
66
66
67
67
1. In the dashboard, make sure that `PPS > 0`.
68
68
69
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/dashboard-view-v2.png" alt-text="Screenshot of a sample dashboard.":::
69
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/dashboard-view-v2.png" alt-text="Screenshot of a sample dashboard.":::
70
70
71
71
1. From the side menu, select **Devices**.
72
72
73
73
1. In the **Devices** window, make sure devices are being discovered.
74
74
75
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/discovered-devices.png" alt-text="Ensure that devices are discovered.":::
75
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/discovered-devices.png" alt-text="Screenshot of the discovered devices.":::
76
76
77
77
1. From the side menu, select **Data Mining**.
78
78
79
79
1. In the **Data Mining** window, select **ALL** and generate a report.
80
80
81
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Generate a new report by using data mining.":::
81
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Screenshot of the generate a new report by using data mining screen.":::
82
82
83
83
1. Make sure the report contains data.
84
84
85
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Ensure that the report contains data.":::
85
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Screenshot of the ensure that the report contains data screen.":::
86
86
87
87
1. From the side menu, select **Trends & Statistics**.
88
88
89
89
1. In the **Trends & Statistics** window, select **Add Widget**.
90
90
91
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/add-widget.png" alt-text="Add a widget by selecting it.":::
91
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/add-widget.png" alt-text="Screenshot of the add a widget by selecting it.":::
92
92
93
93
1. Add a widget and make sure it shows data.
94
94
95
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/widget-data.png" alt-text="Ensure that the widget is showing data.":::
95
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/widget-data.png" alt-text="Screenshot of the widget showing data.":::
96
96
97
97
1. From the side menu, select **Alerts**. The **Alerts** window appears.
98
98
99
99
1. Make sure the alerts were created.
100
100
101
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alerts-created.png" alt-text="Ensure that alerts were created.":::
102
-
101
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alerts-created.png" alt-text="Screenshot of the alerts were created.":::
103
102
104
-
### Investigate a lack of expected alerts
103
+
### Investigate a lack of expected alerts on the sensor
105
104
106
105
If the **Alerts** window doesn't show an alert that you expected, verify the following:
107
106
108
107
- Check if the same alert already appears in the **Alerts** window as a reaction to a different security instance. If yes, and this alert has not been handled yet, the sensor console does not show a new alert.
109
108
110
-
- Make sure you did not exclude this alert by using the **Alert Exclusion** rules in the management console.
109
+
- Make sure you did not exclude this alert by using the **Alert Exclusion** rules in the management console.
111
110
112
111
### Investigate widgets that show no data
113
112
114
113
When the widgets in the **Trends & Statistics** window show no data, do the following:
115
114
116
115
-[Check system performance](#check-system-performance).
117
116
118
-
- Make sure the time and region settings are properly configured and not set to a future time.
117
+
- Make sure the time and region settings are properly configured and not set to a future time.
119
118
120
119
### Investigate a device map that shows only broadcasting devices
121
120
122
121
When devices shown on the map appear not connected to each other, something might be wrong with the SPAN port configuration. That is, you might be seeing only broadcasting devices and no unicast traffic.
123
122
124
-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/broadcasting-devices.png" alt-text="View your broadcasting devices.":::
123
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/broadcasting-devices.png" alt-text="Screenshot of the broadcasting devices.":::
125
124
126
125
In such a case, validate that you only the broadcast traffic and then ask the network engineer to fix the SPAN port configuration so that you can see the unicast traffic as well.
127
126
@@ -139,7 +138,7 @@ You can configure a standalone sensor and a management console, with the sensors
139
138
140
139
To connect a standalone sensor to NTP:
141
140
142
-
-[Contact the Support team for assistance](https://support.microsoft.com/en-us/supportforbusiness/productselection?sapId=82c88f35-1b8e-f274-ec11-c6efdd6dd099).
141
+
-[Contact the Support team for assistance](https://support.microsoft.com/supportforbusiness/productselection?sapId=82c88f35-1b8e-f274-ec11-c6efdd6dd099).
143
142
144
143
To connect a sensor controlled by the management console to NTP:
145
144
@@ -151,9 +150,9 @@ Sometimes ICS devices are configured with external IP addresses. These ICS devic
151
150
152
151
Another indication of the same problem is when multiple internet-related alerts appear.
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alert-problems.png" alt-text="Screenshot of the multiple internet-related alerts.":::
155
154
156
-
To fix the configuration:
155
+
**To fix the configuration**:
157
156
158
157
1. Right-click the cloud icon on the device map and select **Export IP Addresses**. Copy the public ranges that are private, and add them to the subnet list. For more information, see [Configure subnets](how-to-control-what-traffic-is-monitored.md#configure-subnets).
159
158
@@ -167,13 +166,13 @@ To save your network resources, you can limit the interface bandwidth that the s
167
166
168
167
To limit the interface bandwidth, use the `cyberx-xsense-limit-interface` CLI tool that needs to be run with sudo permissions. The tool gets the following arguments:
169
168
170
-
-`* -i`: interfaces (example: eth0).
169
+
-`* -i`: interfaces (example: eth0).
171
170
172
-
-`* -l`: limit (example: 30 kbit / 1 mbit). You can use the following bandwidth units: kbps, mbps, kbit, mbit, or bps.
171
+
-`* -l`: limit (example: 30 kbit / 1 mbit). You can use the following bandwidth units: kbps, mbps, kbit, mbit, or bps.
173
172
174
-
-`* -c`: clear (to clear the interface bandwidth limitation).
173
+
-`* -c`: clear (to clear the interface bandwidth limitation).
175
174
176
-
To tweak the quality of service:
175
+
**To tweak the Quality of Service (QoS)**:
177
176
178
177
1. Sign in to the sensor CLI as a Defender for IoT user, and enter `sudo cyberx-xsense-limit-interface-I eth0 -l value`.
179
178
@@ -186,7 +185,7 @@ To tweak the quality of service:
### Investigate a lack of expected alerts on the management console
190
189
191
190
If an expected alert is not shown in the **Alerts** window, verify the following:
192
191
@@ -202,9 +201,9 @@ The default is 50. This means that in one communication session between an appli
202
201
203
202
To limit the number of alerts, use the `notifications.max_number_to_report` property available in `/var/cyberx/properties/management.properties`. No restart is needed after you change this property.
204
203
205
-
To tweak the quality of service:
204
+
**To tweak the Quality of Service (QoS)**:
206
205
207
-
1. Sign in as a Defender for IoT user.
206
+
1. Sign in as a Defender for IoT user.
208
207
209
208
1. Verify the default values:
210
209
@@ -234,19 +233,19 @@ To tweak the quality of service:
234
233
235
234
1. Save the changes. No restart is required.
236
235
237
-
## Export information for troubleshooting
236
+
## Export information from the sensor for troubleshooting
238
237
239
-
In addition to tools for monitoring and analyzing your network, you can send information to the support team for further investigation. When you export logs, the sensor will automatically generate a one-time password (OTP), unique for the exported logs, in a separate text file.
238
+
In addition to tools for monitoring and analyzing your network, you can send information to the support team for further investigation. When you export logs, the sensor will automatically generate a one-time password (OTP), unique for the exported logs, in a separate text file.
240
239
241
-
To export logs:
240
+
**To export logs**:
242
241
243
242
1. On the left pane, select **System Settings**.
244
243
245
244
1. Select **Export Logs**.
246
245
247
-
:::image type="content" source="media/how-to-export-information-for-troubleshooting/export-a-log.png" alt-text="Export a log to system support.":::
246
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/sensor-export-log.png" alt-text="Screenshot of the export a log to system support screen.":::
248
247
249
-
1. In the **File Name**box, enter the file name that you want to use for the log export. The default is the current date.
248
+
1. In the **File Name**field, enter the file name that you want to use for the log export. The default is the current date.
250
249
251
250
1. To define what data you want to export, select the data categories:
252
251
@@ -275,7 +274,41 @@ The exported logs are added to the **Archived Logs** list. Send the OTP to the s
275
274
276
275
The list of archived logs can contain up to five items. If the number of items in the list goes beyond that number, the earliest item is deleted.
277
276
278
-
## See also
277
+
## Export audit log from the management console
278
+
279
+
Audit logs record key information at the time of occurrence. Audit logs are useful when you are trying to figure out what changes were made, and by who. Audit logs can be exported in the management console, and contain the following information:
|**Management Console Upgrade**| The upgrade file used |
290
+
|**Sensor upgrade retry**| Sensor ID |
291
+
|**Uploaded TI package**| No additional information recorded. |
292
+
293
+
**To export the audit log**:
294
+
295
+
1. In the management console, in the left pane, select **System Settings**.
296
+
297
+
1. Select **Export**.
298
+
299
+
1. In the File Name field, enter the file name that you want to use for the exported log. If no name is entered, the default file name will be the current date.
300
+
301
+
1. Select **Audit Logs**.
302
+
303
+
1. Select **Export**.
304
+
305
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/audit-logs-export.png" alt-text="Screenshot of the select Audit Logs and then select Export to create your file screen.":::
306
+
307
+
The exported log is added to the **Archived Logs** list. Select the :::image type="icon" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/eye-icon.png" border="false"::: button to view the OTP. Send the OTP string to the support team in a separate message from the exported logs. The support team will be able to extract exported logs only by using the unique OTP that's used to encrypt the logs.
308
+
309
+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/archived-files.png" alt-text="Screenshot of the file you created in the archived files section of the Export Troubleshooting Information window.":::
0 commit comments