Microsoft Defender for IoT
Identity protection

Track Network and Sensor Activity with the Event Timeline in Microsoft Defender for IoT

In brief

The article received updated metadata, wording, and clearer procedure structure for filtering, viewing, exporting, and manually adding timeline events.

What Defender admins need to know

Administrators can follow the event-timeline procedures more easily, including the stated Admin or Security Analyst access requirement.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Track network and sensor activity with the event timeline

Activity detected by your Microsoft Defender for IoT sensors detect is recorded in the event timeline. Activity includes alerts and alert management actions, network events, and user operations such as user sign-in or user deletion.

The OT sensor's event timeline provides a chronological view and context of all network activity,activity to help determine the cause and effect of incidents. The timeline view makes it easy to extract information from network events,events and more efficiently analyze alerts and events observed on the network. With the ability to store vast amounts of data, the event timeline view can be a valuable resource for security teams to perform investigations and gain a deeper understanding of network activity.

Use the event timeline during investigations,investigations to understand and analyze the chain of events that preceded and followed an attack or incident. The centralized view of multiple security-related events on the same timeline helps to identify patterns and correlations, and enable security teams to quickly assess the impact of incidents and respond accordingly.

For more information, see:

Permissions required to view the event timeline

Before you perform the event timeline procedures described in this section,article, make sure that you have access to an OT sensor as an Admin or Security Analyst role. For more information, see On-premises users and roles for OT monitoring with Defender for IoT.

View the event timeline

  1. Sign in to the sensor console,console and select Event Timeline from the left menu.

  2. Review and filter the events as needed.

  3. Select an event row to view the event details in a pane on the right, where you can also filter to view events of related devices. The User Operations filter is on by default, you can select to hide or show user events as needed.

    For example:

You can also view the event timeline of a specific device from the Device inventory.

To view the event timeline of a specific device:device:

  1. In the sensor console, go to Device inventory.

Filter events on the timeline

Use the following steps to filter events shown on the timeline:

  1. On the event timeline page, select Add filter to specify the events shown.

  2. Select the filter Type. Use any of the following options to filter the devices shown:

Export the event timeline to CSV

You can export the event timeline to a CSV file, thefile. The exported data is according to any filters applied when exporting.

To export the event timeline:timeline:

On the Event timeline page, select Export from the top menu to export the event timeline to a CSV file.

Create an event

In addition to viewing the events that the sensor has detected, you can manually add events to the timeline. This process is useful if an external system event impacts your network,network and you want to record it on the timeline.

To manually add an event to the timeline:

  1. On the Event timeline page, select Create Event.

  2. In the Create Event dialog, add the following event details:

    • Type.: Specify the event type (Info, Notice, or Alert).

    • Timestamp.: Set the date and time of the event.

    • Device.: Select the device the event should be connected with.

    • Description.: Provide a description of the event.

  3. Select Save to add the event to the timeline.

The amount of data that can be stored in the event timeline depends on various factors, such as the size of the network, the frequency of events, and the storage capacity of your sensor. The data stored in the event timeline can include information about network traffic, security events, and other relevant data points.

The maximum number of events shown in the event timeline is dependent on the OT appliance sizing and hardware profile selected during sensor installation. Each hardware profile has a maximum capacity of events. For more information on the maximum event capacity for eachby OT appliance hardware profile, see OT event timeline retention.

Next stepsRelated content

For more information, see: