Skip to content

Commit f11ee0b

Browse files
Merge pull request #178693 from ElazarK/sentinel-fix
Update how-to-configure-with-sentinel.md
2 parents a2f6e17 + db2beea commit f11ee0b

File tree

1 file changed

+13
-9
lines changed

1 file changed

+13
-9
lines changed

articles/defender-for-iot/organizations/how-to-configure-with-sentinel.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,34 +2,38 @@
22
title: Configure Azure Sentinel with Defender for IoT for organizations
33
description: Explains how to configure Azure Sentinel to receive data from your Defender for IoT solution.
44
ms.topic: how-to
5-
ms.date: 06/14/2021
5+
ms.date: 11/08/2021
66
---
77

88
# Connect your data from Defender for IoT for organizations to Azure Sentinel (Public preview)
99

10-
Use the Defender for IoT connector to stream all your Defender for IoT events into Azure Sentinel.
10+
Use the Defender for IoT connector to stream all your Defender for IoT events into Azure Sentinel.
1111

12-
This integration enables organizations to quickly detect multistage attacks that often cross IT and OT boundaries. Additionally, Defender for IoT’s integration with Azure Sentinel's security orchestration, automation, and response (SOAR) capabilities enables automated response and prevention using built-in OT-optimized playbooks.
12+
This integration enables organizations to quickly detect multistage attacks that often cross IT and OT boundaries. Additionally, Defender for IoT’s integration with Azure Sentinel's security orchestration, automation, and response (SOAR) capabilities enable automated response and prevention using built-in OT-optimized playbooks.
1313

1414
## Prerequisites
1515

1616
- **Read** and **Write** permissions on the Workspace onto which Azure Sentinel is deployed
17+
1718
- **Defender for IoT** must be **enabled** on your relevant IoT Hub(s)
19+
1820
- You must have **Contributor** permissions on the **Subscription** you want to connect
1921

2022
## Connect to Defender for IoT
2123

2224
1. In Azure Sentinel, select **Data connectors** and then select the **Defender for IoT** (may still be called Azure Security Center for IoT) from the gallery.
2325

24-
1. From the bottom of the right pane, click **Open connector page**.
26+
1. From the bottom of the right pane, select **Open connector page**.
27+
28+
1. Select **Connect**, next to each subscription whose alerts and device alerts you want to stream into Azure Sentinel.
2529

26-
1. Click **Connect**, next to each IoT Hub subscription whose alerts and device alerts you want to stream into Azure Sentinel.
27-
- You will receive an error message if Defender for IoT is not enabled on at least one IoT Hub within a subscription. Enable Defender for IoT within the IoT Hub to remove the error.
30+
> [!NOTE]
31+
> You will receive an error message if Defender for IoT is not enabled on at least one IoT Hub within that subscription. Enable Defender for IoT within the IoT Hub to remove the error.
2832
29-
1. You can decide whether you want the alerts from Defender for IoT to automatically generate incidents in Azure Sentinel. Under **Create incidents**, select **Enable** to enable the default analytics rule to automatically create incidents from the generated alerts. This rule can be changed or edited under **Analytics** > **Active rules**.
33+
1. You can decide whether you want the alerts from Defender for IoT to automatically generate incidents in Azure Sentinel. Under **Create incidents**, select **Enable** to enable the default analytics rule to automatically create incidents from the generated alerts. This rule can be changed or edited under **Analytics** > **Active rules**.
3034

3135
> [!NOTE]
32-
> It can take 10 seconds or more for the **Subscription** list to refresh after making connection changes.
36+
> It can take 10 seconds or more for the **Subscription** list to refresh after making connection changes.
3337
3438
## Log Analytics alert view
3539

@@ -51,4 +55,4 @@ After connecting a **Subscription**, the hub data is available in Azure Sentinel
5155

5256
In this document, you learned how to connect Defender for IoT to Azure Sentinel. To learn more about threat detection and security data access, see the following articles:
5357

54-
- Learn how to use Azure Sentinel to [Quickstart: Get started with Azure Sentinel](../../sentinel/get-visibility.md).
58+
- Learn how to use Azure Sentinel to [Quickstart: Get started with Azure Sentinel](../../sentinel/get-visibility.md)

0 commit comments

Comments
 (0)