Skip to content

Commit e5b1809

Browse files
authored
Merge pull request #222600 from Shereen-Bhar/refresh-port-and-vlan-names-page
Refresh port and VLAN names page
2 parents 3deef82 + 26f4c0c commit e5b1809

File tree

3 files changed

+49
-40
lines changed

3 files changed

+49
-40
lines changed

articles/defender-for-iot/organizations/how-to-create-data-mining-queries.md

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ Data mining query data is continuously saved until a device is deleted, and is a
1717

1818
To create data mining reports, you must be able to access the OT network sensor you want to generate data for as an **Admin** or **Security Analyst** user.
1919

20-
For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md)
20+
For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md).
2121

2222
## View an OT sensor predefined data mining report
2323

@@ -54,7 +54,7 @@ Create your own custom data mining report if you have reporting needs not covere
5454
| **Choose category** | Select the categories to include in your report. |
5555
| **Order by** | Select to sort your data by category or by activity. |
5656
| **Filter by** | Define a filter for your report using any of the following parameters: <br><br> - **Results within the last**: Enter a number and then select **Minutes**, **Hours**, or **Days** <br> - **IP address / MAC address / Port**: Enter one or more IP addresses, MAC addresses, and ports to filter into your report. Enter a value and then select + to add it to the list.<br> - **Device group**: Select one or mode device groups to filter into your report. |
57-
| **Add filter type** | Select to add any of the following filter types into your report. <br><br> - Transport (GENERIC) <br> - Protocol (GENERIC) <br> - TAG (GENERIC) <br> - Maximum value (GENERIC) <br> - State (GENERIC) <br> - Minimum value (GENERIC) <br><br> Enter a value in the relevant field and then select + to add it to the list. |
57+
| **Add filter type** | Select to add any of the following filter types into your report. <br><br> - Transport (GENERIC) <br> - Protocol (GENERIC) <br> - TAG (GENERIC) <br> - Maximum value (GENERIC) <br> - State (GENERIC) <br> - Minimum value (GENERIC) <br><br> Enter a value in the relevant field and then select + to add it to the list. |
5858

5959
1. Select **Save**. Your data mining report is shown in the **My reports** area. For example:
6060

@@ -82,9 +82,7 @@ Sign into an on-premises management console to view [out-of-the-box data mining
8282

8383
**To view a data mining report from an on-premises management console**:
8484

85-
Sign into your on-premises management console and select
86-
87-
1. **Reports** on the left.
85+
1. Sign into your on-premises management console and select **Reports** on the left.
8886

8987
1. From the **Sensors** drop-down list, select the sensor for which you want to generate the report.
9088

@@ -98,8 +96,8 @@ The page lists the current report data. Select :::image type="icon" source="medi
9896

9997
- Continue creating other reports for more security data from your OT sensor. For more information, see:
10098

101-
- [Risk assessment reporting](how-to-create-risk-assessment-reports.md)
102-
103-
- [Attack vector reporting](how-to-create-attack-vector-reports.md)
104-
105-
- [Create trends and statistics dashboards](how-to-create-trends-and-statistics-reports.md)
99+
- [Risk assessment reporting](how-to-create-risk-assessment-reports.md)
100+
101+
- [Attack vector reporting](how-to-create-attack-vector-reports.md)
102+
103+
- [Create trends and statistics dashboards](how-to-create-trends-and-statistics-reports.md)
Lines changed: 41 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -1,54 +1,65 @@
11
---
2-
title: Enhance port and VLAN name resolution in Defender for IoT
3-
description: Customize port and VLAN names on your sensors
4-
ms.date: 01/02/2022
2+
title: Customize port and VLAN names on OT network sensors - Microsoft Defender for IoT
3+
description: Learn how to customize port and VLAN names on Microsoft Defender for IoT OT network sensors.
4+
ms.date: 01/12/2023
55
ms.topic: how-to
66
---
77

8-
# Customize port and VLAN names
8+
# Customize port and VLAN names on OT network sensors
99

10-
You can customize port and VLAN names on your sensors to enrich device resolution.
10+
Enrich device data shown in Defender for IoT by customizing port and VLAN names on your OT network sensors.
1111

12-
## Customize a port name
12+
For example, you might want to assign a name to a non-reserved port that shows unusually high activity in order to call it out, or assign a name to a VLAN number to identify it quicker.
1313

14-
Microsoft Defender for IoT automatically assigns names to most universally reserved ports, such as DHCP or HTTP. You can customize port names for other ports that Defender for IoT detects. For example, you might assign a name to a non-reserved port because that port shows unusually high activity. Names appear when you view device groups from the device map, or when you create reports that provide port information.
14+
## Prerequisites
1515

16-
Customize a name as follows:
16+
To customize port and VLAN names, you must be able to access the OT network sensor as an **Admin** user.
1717

18-
1. Select **System Settings**. Under **Network monitoring**, select **Port Naming**.
19-
2. Select **Add port**.
20-
3. Enter the port number, select the protocol (TCP, UDP, both) and type in a name.
21-
4. Select **Save**.
18+
For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md).
19+
20+
## Customize names of detected ports
21+
22+
Defender for IoT automatically assigns names to most universally reserved ports, such as DHCP or HTTP. However, you might want to customize the name of a specific port to highlight it, such as when you're watching a port with unusually high detected activity.
23+
24+
Port names are shown in Defender for IoT when [viewing device groups from the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#group-highlight-and-filters-tools), or when you create OT sensor reports that include port information.
25+
26+
**To customize a port name:**
27+
28+
1. Sign into your OT sensor as an **Admin** user.
29+
30+
1. Select **System settings** on the left and then, under **Network monitoring**, select **Port Naming**.
31+
32+
1. In the **Port naming** pane that appears, enter the port number you want to name, the port's protocol, and a meaningful name. Supported protocol values include: **TCP**, **UDP**, and **BOTH**.
33+
34+
1. Select **+ Add port** to customize an additional port, and **Save** when you're done.
2235

2336
## Customize a VLAN name
2437

25-
You can enrich device inventory data with device VLAN numbers and tags.
38+
VLANs are either discovered automatically by the OT network sensor or added manually. Automatically discovered VLANs can't be edited or deleted, but manually added VLANs require a unique name. If a VLAN isn't explicitly named, the VLAN's number is shown instead.
2639

27-
- VLANs support is based on 802.1q (up to VLAN ID 4094). VLANS can be discovered automatically by the sensor or added manually.
28-
- Automatically discovered VLANs can't be edited or deleted. You should add a name to each VLAN, if you don't add a name, the VLAN number will appear when VLAN information is reported.
29-
- When you add a manual VLN, you must add a unique name. These VLANs can be edited and deleted.
30-
- VLAN names can contain up to 50 ASCII characters.
40+
VLAN's support is based on 802.1q (up to VLAN ID 4094).
3141

32-
## Before you start
33-
> [!NOTE]
34-
> VLAN names are not synchronized between the sensor and the management console. You need to define the name on the management console as well.
35-
For Cisco switches, add the following line to the span configuration: `monitor session 1 destination interface XX/XX encapsulation dot1q`. In that command, *XX/XX* is the name and number of the port.
42+
VLAN names aren't synchronized between the OT network sensor and the on-premises management console. If you want to view customized VLAN names on the on-premises management console, [define the VLAN names](how-to-manage-the-on-premises-management-console.md#define-vlan-names) there as well.
3643

37-
To configure VLAN names:
44+
**To configure VLAN names on an OT network sensor:**
3845

39-
1. On the side menu, select **System Settings**.
46+
1. Sign in to your OT sensor as an **Admin** user.
4047

41-
2. In the **System Settings** window, select **VLAN**.
48+
1. Select **System Settings** on the left and then, under **Network monitoring**, select **VLAN Naming**.
4249

43-
:::image type="content" source="media/how-to-enrich-asset-information/edit-vlan.png" alt-text="Use the system settings to edit your VLANs.":::
50+
1. In the **VLAN naming** pane that appears, enter a VLAN ID and unique VLAN name. VLAN names can contain up to 50 ASCII characters.
4451

45-
3. Add a unique name next to each VLAN ID.
52+
1. Select **+ Add VLAN** to customize an additional VLAN, and **Save** when you're done.
4653

54+
1. **For Cisco switches**: Add the `monitor session 1 destination interface XX/XX encapsulation dot1q` command to the SPAN port configuration, where *XX/XX* is the name and number of the port.
4755

4856
## Next steps
4957

50-
View enriched device information in various reports:
58+
> [!div class="nextstepaction"]
59+
> [Investigate detected devices from the OT sensor device inventory](how-to-investigate-sensor-detections-in-a-device-inventory.md)
60+
61+
> [!div class="nextstepaction"]
62+
> [Create sensor trends and statistics reports](how-to-create-trends-and-statistics-reports.md)
5163
52-
- [Investigate sensor detections in a device inventory](how-to-investigate-sensor-detections-in-a-device-inventory.md)
53-
- [Sensor trends and statistics reports](how-to-create-trends-and-statistics-reports.md)
54-
- [Sensor data mining queries](how-to-create-data-mining-queries.md)
64+
> [!div class="nextstepaction"]
65+
> [Create sensor data mining queries](how-to-create-data-mining-queries.md)

0 commit comments

Comments
 (0)