You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/integrate-overview.md
+18-26Lines changed: 18 additions & 26 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,15 +9,8 @@ ms.topic: overview
9
9
10
10
Integrate Microsoft Defender for Iot with partner services to view partner data in Defender for IoT, or to view Defender for IoT data in a partner service.
11
11
12
-
## Azure Monitor
13
-
14
-
|Name |Description |Support scope |Supported by |Learn more |
|**Log Analytics**| Store Defender for IoT data in a Log Analytics workspace, and then create and use Azure Monitor workbooks in Defender for IoT to visualize the data stored in Log Analytics. | - OT, Enterprise IoT, and device builder data <br><br>- Cloud-connected sensors only | Microsoft | TBD |
17
-
18
12
## Axonius
19
13
20
-
<<<<<<< HEAD
21
14
22
15
|Name |Description |Support scope |Supported by |Learn more |
|**Fortinet**| Send Defender for IoT data to Fortinet services for: <br><br>- Enhanced network visibility in FortiSIEM<br>- Extra abilities in FortiGate to stop anomalous behavior | - OT networks only<br>- Locally managed sensors only | Fortinet |[Integrate Fortinet with Microsoft Defender for IoT](tutorial-fortinet.md)|
50
43
44
+
## LogRhythm
45
+
46
+
|Name |Description |Support scope |Supported by |Learn more |
|**LogRhythm**| Forward Defender for IoT alerts to LogRhythm. | - OT networks only<br>- Locally managed sensors only | LogRhythm |[Integrate LogRhythm with Microsoft Defender for IoT](integrations/logrhythm.md)|
49
+
50
+
## Micro Focus ArcSight
51
+
52
+
|Name |Description |Support scope |Supported by |Learn more |
|**Micro Focus ArcSight**| Forward Defender for IoT alerts to ArcSight. | - OT networks only<br>- Locally managed sensors only | Micro Focus |[Integrate ArcSight with Microsoft Defender for IoT](integrations/arcsight.md)|
55
+
51
56
## Microsoft Defender for Endpoint
52
57
53
58
|Name |Description |Support scope |Supported by |Learn more |
@@ -60,7 +65,6 @@ Integrate Microsoft Defender for Iot with partner services to view partner data
|**Defender for IoT data connector**| Displays Defender for IoT data in Microsoft Sentinel, supporting end-to-end SOC investigations for Defender for IoT alerts. | - OT networks only <br>- Cloud-connected sensors only | Microsoft |[Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended)|
62
67
|**IoT/OT Threat Monitoring with Defender for IoT**| Provides additional security content for Defender for IoT data in Microsoft Sentinel | - OT networks only <br>- Cloud-connected sensors only | Microsoft |[Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended)|
63
-
| TBD name (Legacy) | TBD | - OT networks only <br><br>Locally connected sensors only | TBD |
64
68
65
69
66
70
## Palo Alto
@@ -75,6 +79,12 @@ Integrate Microsoft Defender for Iot with partner services to view partner data
|**QRadar**| Forward Defender for IoT alerts to IBM QRadar. | - OT networks only<br>- Locally managed sensors only | Qradar |[Integrate Qradar with Microsoft Defender for IoT](tutorial-qradar.md)|
77
81
82
+
## RSA NetWitness
83
+
84
+
|Name |Description |Support scope |Supported by |Learn more |
|**Splunk**| Send Defender for IoT alerts to Splunk | - OT networks only<br>- Locally managed sensors only | Splunk |[Integrate Splunk with Microsoft Defender for IoT](tutorial-splunk.md)|
98
108
99
-
|**LogRhythm**| Forward Defender for IoT alerts to LogRhythm. |[Integrate LogRhythm with Microsoft Defender for IoT](integrations/logrhythm.md)|
100
-
101
-
|**RSA NetWitness**| Forward Defender for IoT alerts to RSA NetWitness |[Integrate RSA NetWitness with Microsoft Defender for IoT](integrations/netwitness.md) <br>[CyberX Platform - RSA NetWitness CEF Parser Implementation Guide](https://community.netwitness.com//t5/netwitness-platform-integrations/cyberx-platform-rsa-netwitness-cef-parser-implementation-guide/ta-p/554364)|
102
-
=======
103
-
|Partner service |Description | Learn more |
104
-
|---------|---------|---------|
105
-
|**ArcSight**| Forward Defender for IoT alerts to ArcSight. |[Integrate ArcSight with Microsoft Defender for IoT](integrations/arcsight.md)|
106
-
|**Aruba ClearPass**| Share Defender for IoT data with ClearPass Security Exchange and update the ClearPass Policy Manager Endpoint Database with Defender for IoT data. |[Integrate ClearPass with Microsoft Defender for IoT](tutorial-clearpass.md)|
107
-
|**CyberArk**| Send CyberArk PSM syslog data on remote sessions and verification failures to Defender for IoT for data correlation. |[Integrate CyberArk with Microsoft Defender for IoT](tutorial-cyberark.md)|
108
-
|**Forescout**| Automate actions in Forescout based on activity detected by Defender for IoT, and correlate Defender for IoT data with other *Forescout eyeExtended* modules that oversee monitoring, incident management, and device control. |[Integrate Forescout with Microsoft Defender for IoT](tutorial-forescout.md)|
109
-
|**Fortinet**| Send Defender for IoT data to Fortinet services for: <br><br>- Enhanced network visibility in FortiSIEM<br>- Extra abilities in FortiGate to stop anomalous behavior |[Integrate Fortinet with Microsoft Defender for IoT](tutorial-fortinet.md)|
110
-
|**Palo Alto**|Use Defender for IoT data to block critical threats with Palo Alto firewalls, either with automatic blocking or with blocking recommendations. |[Integrate Palo-Alto with Microsoft Defender for IoT](tutorial-palo-alto.md)|
111
-
|**QRadar**|Forward Defender for IoT alerts to IBM QRadar. |[Integrate Qradar with Microsoft Defender for IoT](tutorial-qradar.md)|
112
-
|**ServiceNow**| View Defender for IoT device detections, attributes, and connections in ServiceNow. |[Integrate ServiceNow with Microsoft Defender for IoT](tutorial-servicenow.md)|
113
-
|**Splunk**| Send Defender for IoT alerts to Splunk |[Integrate Splunk with Microsoft Defender for IoT](tutorial-splunk.md)|
114
-
|**Axonius Cybersecurity Asset Management**| Import and manage device inventory discovered by Defender for IoT in your Axonius instance. |[Axonius documentation](https://docs.axonius.com/docs/azure-defender-for-iot)|
115
-
|**Skybox**| Import vulnerability occurrence data discovered by Defender for IoT in your Skybox platform. |[Skybox documentation](https://docs.skyboxsecurity.com) <br><br> [Skybox integration page](https://www.skyboxsecurity.com/products/integrations)|
0 commit comments