Skip to content

Commit 5d97ebf

Browse files
authored
Merge pull request #170109 from ElazarK/cm-audit
CM Audit
2 parents 0220774 + 08949a4 commit 5d97ebf

File tree

7 files changed

+72
-39
lines changed

7 files changed

+72
-39
lines changed

articles/defender-for-iot/organizations/how-to-troubleshoot-the-sensor-and-on-premises-management-console.md

Lines changed: 72 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -1,40 +1,40 @@
11
---
22
title: Troubleshoot the sensor and on-premises management console
33
description: Troubleshoot your sensor and on-premises management console to eliminate any problems you might be having.
4-
ms.date: 05/10/2021
4+
ms.date: 10/17/2021
55
ms.topic: article
66
---
77
# Troubleshoot the sensor and on-premises management console
88

99
This article describes basic troubleshooting tools for the sensor and the on-premises management console. In addition to the items described here, you can check the health of your system in the following ways:
1010

11-
**Alerts**: An alert is created when the sensor interface that monitors the traffic is down.
11+
**Alerts**: An alert is created when the sensor interface that monitors the traffic is down.
1212

13-
**SNMP**: Sensor health is monitored through SNMP. Azure Defender for IoT responds to SNMP queries sent from an authorized monitoring server.
13+
**SNMP**: Sensor health is monitored through SNMP. Azure Defender for IoT responds to SNMP queries sent from an authorized monitoring server.
1414

1515
**System notifications**: When a management console controls the sensor, you can forward alerts about failed sensor backups and disconnected sensors.
1616

1717
## Sensor troubleshooting tools
1818

19-
### Investigate password failure at initial sign-in
19+
### Investigate password failure at initial sign in
2020

2121
When signing into a preconfigured Arrow sensor for the first time, you'll need to perform password recovery.
2222

23-
To recover your password:
23+
**To recover your password**:
2424

25-
1. On the Defender for IoT sign-in screen, select **Password recovery**. The **Password recovery** screen opens.
25+
1. On the Defender for IoT sign in screen, select **Password recovery**. The **Password recovery** screen opens.
2626

2727
1. Select either **CyberX** or **Support**, and copy the unique identifier.
2828

2929
1. Navigate to the Azure portal and select **Sites and Sensors**.
3030

3131
1. Select the **More Actions** drop down menu and select **Recover on-premises management console password**.
3232

33-
:::image type="content" source="media/how-to-create-and-manage-users/recover-password.png" alt-text="Select your sensor and select the recover on-premises management console password option.":::
33+
:::image type="content" source="media/how-to-create-and-manage-users/recover-password.png" alt-text=" Screenshot of the recover on-premises management console password option.":::
3434

3535
1. Enter the unique identifier that you received on the **Password recovery** screen and select **Recover**. The `password_recovery.zip` file is downloaded.
3636

37-
:::image type="content" source="media/how-to-create-and-manage-users/enter-identifier.png" alt-text="Enter the unique identifier and then select recover.":::
37+
:::image type="content" source="media/how-to-create-and-manage-users/enter-identifier.png" alt-text="Screenshot of the enter the unique identifier and then select recover.":::
3838

3939
> [!NOTE]
4040
> Don't alter the password recovery file. It's a signed file and won't work if you tamper with it.
@@ -53,75 +53,74 @@ To recover your password:
5353
An indicator appears at the top of the console when the sensor recognizes that there's no traffic on one of the configured ports. This indicator is visible to all users.
5454

5555
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/no-traffic-detected.png" alt-text="Screenshot of the alert that no traffic was detected.":::
56-
56+
5757
When this message appears, you can investigate where there's no traffic. Make sure the span cable is connected and there was no change in the span architecture.
5858

5959
For support and troubleshooting information, contact [Microsoft Support](https://support.serviceshub.microsoft.com/supportforbusiness/create?sapId=82c88f35-1b8e-f274-ec11-c6efdd6dd099).
6060

61-
### Check system performance
61+
### Check system performance
6262

6363
When a new sensor is deployed or, for example, the sensor is working slowly or not showing any alerts, you can check system performance.
6464

65-
To check system performance:
65+
**To check system performance**:
6666

6767
1. In the dashboard, make sure that `PPS > 0`.
6868

69-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/dashboard-view-v2.png" alt-text="Screenshot of a sample dashboard.":::
69+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/dashboard-view-v2.png" alt-text="Screenshot of a sample dashboard.":::
7070

7171
1. From the side menu, select **Devices**.
7272

7373
1. In the **Devices** window, make sure devices are being discovered.
7474

75-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/discovered-devices.png" alt-text="Ensure that devices are discovered.":::
75+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/discovered-devices.png" alt-text="Screenshot of the discovered devices.":::
7676

7777
1. From the side menu, select **Data Mining**.
7878

7979
1. In the **Data Mining** window, select **ALL** and generate a report.
8080

81-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Generate a new report by using data mining.":::
81+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Screenshot of the generate a new report by using data mining screen.":::
8282

8383
1. Make sure the report contains data.
8484

85-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Ensure that the report contains data.":::
85+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/new-report-generated.png" alt-text="Screenshot of the ensure that the report contains data screen.":::
8686

8787
1. From the side menu, select **Trends & Statistics**.
8888

8989
1. In the **Trends & Statistics** window, select **Add Widget**.
9090

91-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/add-widget.png" alt-text="Add a widget by selecting it.":::
91+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/add-widget.png" alt-text="Screenshot of the add a widget by selecting it.":::
9292

9393
1. Add a widget and make sure it shows data.
9494

95-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/widget-data.png" alt-text="Ensure that the widget is showing data.":::
95+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/widget-data.png" alt-text="Screenshot of the widget showing data.":::
9696

9797
1. From the side menu, select **Alerts**. The **Alerts** window appears.
9898

9999
1. Make sure the alerts were created.
100100

101-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alerts-created.png" alt-text="Ensure that alerts were created.":::
102-
101+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alerts-created.png" alt-text="Screenshot of the alerts were created.":::
103102

104-
### Investigate a lack of expected alerts
103+
### Investigate a lack of expected alerts on the sensor
105104

106105
If the **Alerts** window doesn't show an alert that you expected, verify the following:
107106

108107
- Check if the same alert already appears in the **Alerts** window as a reaction to a different security instance. If yes, and this alert has not been handled yet, the sensor console does not show a new alert.
109108

110-
- Make sure you did not exclude this alert by using the **Alert Exclusion** rules in the management console.
109+
- Make sure you did not exclude this alert by using the **Alert Exclusion** rules in the management console.
111110

112111
### Investigate widgets that show no data
113112

114113
When the widgets in the **Trends & Statistics** window show no data, do the following:
115114

116115
- [Check system performance](#check-system-performance).
117116

118-
- Make sure the time and region settings are properly configured and not set to a future time.
117+
- Make sure the time and region settings are properly configured and not set to a future time.
119118

120119
### Investigate a device map that shows only broadcasting devices
121120

122121
When devices shown on the map appear not connected to each other, something might be wrong with the SPAN port configuration. That is, you might be seeing only broadcasting devices and no unicast traffic.
123122

124-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/broadcasting-devices.png" alt-text="View your broadcasting devices.":::
123+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/broadcasting-devices.png" alt-text="Screenshot of the broadcasting devices.":::
125124

126125
In such a case, validate that you only the broadcast traffic and then ask the network engineer to fix the SPAN port configuration so that you can see the unicast traffic as well.
127126

@@ -139,7 +138,7 @@ You can configure a standalone sensor and a management console, with the sensors
139138

140139
To connect a standalone sensor to NTP:
141140

142-
- [Contact the Support team for assistance](https://support.microsoft.com/en-us/supportforbusiness/productselection?sapId=82c88f35-1b8e-f274-ec11-c6efdd6dd099).
141+
- [Contact the Support team for assistance](https://support.microsoft.com/supportforbusiness/productselection?sapId=82c88f35-1b8e-f274-ec11-c6efdd6dd099).
143142

144143
To connect a sensor controlled by the management console to NTP:
145144

@@ -151,9 +150,9 @@ Sometimes ICS devices are configured with external IP addresses. These ICS devic
151150

152151
Another indication of the same problem is when multiple internet-related alerts appear.
153152

154-
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alert-problems.png" alt-text="Multiple internet-related alerts.":::
153+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/alert-problems.png" alt-text="Screenshot of the multiple internet-related alerts.":::
155154

156-
To fix the configuration:
155+
**To fix the configuration**:
157156

158157
1. Right-click the cloud icon on the device map and select **Export IP Addresses**. Copy the public ranges that are private, and add them to the subnet list. For more information, see [Configure subnets](how-to-control-what-traffic-is-monitored.md#configure-subnets).
159158

@@ -167,13 +166,13 @@ To save your network resources, you can limit the interface bandwidth that the s
167166

168167
To limit the interface bandwidth, use the `cyberx-xsense-limit-interface` CLI tool that needs to be run with sudo permissions. The tool gets the following arguments:
169168

170-
- `* -i`: interfaces (example: eth0).
169+
- `* -i`: interfaces (example: eth0).
171170

172-
- `* -l`: limit (example: 30 kbit / 1 mbit). You can use the following bandwidth units: kbps, mbps, kbit, mbit, or bps.
171+
- `* -l`: limit (example: 30 kbit / 1 mbit). You can use the following bandwidth units: kbps, mbps, kbit, mbit, or bps.
173172

174-
- `* -c`: clear (to clear the interface bandwidth limitation).
173+
- `* -c`: clear (to clear the interface bandwidth limitation).
175174

176-
To tweak the quality of service:
175+
**To tweak the Quality of Service (QoS)**:
177176

178177
1. Sign in to the sensor CLI as a Defender for IoT user, and enter `sudo cyberx-xsense-limit-interface-I eth0 -l value`.
179178

@@ -186,7 +185,7 @@ To tweak the quality of service:
186185

187186
## On-premises management console troubleshooting tools
188187

189-
### Investigate a lack of expected alerts
188+
### Investigate a lack of expected alerts on the management console
190189

191190
If an expected alert is not shown in the **Alerts** window, verify the following:
192191

@@ -202,9 +201,9 @@ The default is 50. This means that in one communication session between an appli
202201

203202
To limit the number of alerts, use the `notifications.max_number_to_report` property available in `/var/cyberx/properties/management.properties`. No restart is needed after you change this property.
204203

205-
To tweak the quality of service:
204+
**To tweak the Quality of Service (QoS)**:
206205

207-
1. Sign in as a Defender for IoT user.
206+
1. Sign in as a Defender for IoT user.
208207

209208
1. Verify the default values:
210209

@@ -234,19 +233,19 @@ To tweak the quality of service:
234233

235234
1. Save the changes. No restart is required.
236235

237-
## Export information for troubleshooting
236+
## Export information from the sensor for troubleshooting
238237

239-
In addition to tools for monitoring and analyzing your network, you can send information to the support team for further investigation. When you export logs, the sensor will automatically generate a one-time password (OTP), unique for the exported logs, in a separate text file.
238+
In addition to tools for monitoring and analyzing your network, you can send information to the support team for further investigation. When you export logs, the sensor will automatically generate a one-time password (OTP), unique for the exported logs, in a separate text file.
240239

241-
To export logs:
240+
**To export logs**:
242241

243242
1. On the left pane, select **System Settings**.
244243

245244
1. Select **Export Logs**.
246245

247-
:::image type="content" source="media/how-to-export-information-for-troubleshooting/export-a-log.png" alt-text="Export a log to system support.":::
246+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/sensor-export-log.png" alt-text="Screenshot of the export a log to system support screen.":::
248247

249-
1. In the **File Name** box, enter the file name that you want to use for the log export. The default is the current date.
248+
1. In the **File Name** field, enter the file name that you want to use for the log export. The default is the current date.
250249

251250
1. To define what data you want to export, select the data categories:
252251

@@ -275,7 +274,41 @@ The exported logs are added to the **Archived Logs** list. Send the OTP to the s
275274

276275
The list of archived logs can contain up to five items. If the number of items in the list goes beyond that number, the earliest item is deleted.
277276

278-
## See also
277+
## Export audit log from the management console
278+
279+
Audit logs record key information at the time of occurrence. Audit logs are useful when you are trying to figure out what changes were made, and by who. Audit logs can be exported in the management console, and contain the following information:
280+
281+
| Action | Information logged |
282+
|--|--|
283+
| **Learn, and remediation of alerts** | Alert ID |
284+
| **Password changes** | User, User ID |
285+
| **Login** | User |
286+
| **User creation** | User, User role |
287+
| **Password reset** | User name |
288+
| **Exclusion rules**: </br></br>- Creation </br></br>- Editing </br></br>- Deletion | </br></br>Rule summary </br></br>Rule ID, Rule Summary </br></br>Rule ID |
289+
| **Management Console Upgrade** | The upgrade file used |
290+
| **Sensor upgrade retry** | Sensor ID |
291+
| **Uploaded TI package** | No additional information recorded. |
292+
293+
**To export the audit log**:
294+
295+
1. In the management console, in the left pane, select **System Settings**.
296+
297+
1. Select **Export**.
298+
299+
1. In the File Name field, enter the file name that you want to use for the exported log. If no name is entered, the default file name will be the current date.
300+
301+
1. Select **Audit Logs**.
302+
303+
1. Select **Export**.
304+
305+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/audit-logs-export.png" alt-text="Screenshot of the select Audit Logs and then select Export to create your file screen.":::
306+
307+
The exported log is added to the **Archived Logs** list. Select the :::image type="icon" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/eye-icon.png" border="false"::: button to view the OTP. Send the OTP string to the support team in a separate message from the exported logs. The support team will be able to extract exported logs only by using the unique OTP that's used to encrypt the logs.
308+
309+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/archived-files.png" alt-text="Screenshot of the file you created in the archived files section of the Export Troubleshooting Information window.":::
310+
311+
## Next steps
279312

280313
- [View alerts](how-to-view-alerts.md)
281314

Loading
Loading
Loading
Loading
Loading

0 commit comments

Comments
 (0)