Microsoft Defender for IoT
General

View and Manage Alerts on the Azure Portal

In brief

The article adds clearer navigation for viewing alerts, a considerations section, refreshed grouping-option formatting, and minor wording, punctuation, metadata, and title updates.

What Defender admins need to know

Use the revised guidance when helping administrators view and manage Defender for IoT alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Before you view or manage alerts in the Azure portal, make sure the following prerequisites are met:

  • To have alerts in Defender for IoT,IoT, you must have an OT sensor onboarded, and network data streaming into Defender for IoT.

  • To view alerts on the Azure portal,portal, you must have access as a Security Reader, Security Admin, Contributor, or Owner

  • To manage alerts on the Azure portal,portal, you must have access as a Security Admin, Contributor, or Owner. Alert management activities include modifying their statuses or severities, Learning an alert, accessing PCAP data, or using alert suppression rules.

For more information, see Azure user roles and permissions for Defender for IoT.

View alerts on the Azure portal

To view alerts in the Azure portal, follow these steps:

  1. In Defender for IoT on the Azure portal, select the Alerts page on the left. By default, the following details are shown in the grid:

    | Column | Description | Name | The alert title. | | Site | The site associated with the sensor that detected the alert, as listed on the Sites and sensors page.| | Engine | The Defender for IoT detection engine that detected the activity and triggered the alert.

    Note: A value of Micro-agent indicates that the event was triggered by the Defender for IoT Device Builder platform. | | Last detection | The last time the alert was detected.

    - If an alert's status is New, and the same traffic is seen again, the Last detection time is updated for the same alert.
    - If the alert's status is Closed and traffic is seen again, the Last detection time is not updated, and a new alert is triggered.

    Note: While the sensor console displays an alert's Last detection field in real-time, Defender for IoT in the Azure portal maymight take up to one hour to display the updated time. This delay in the Azure portal explains why the last detection time in the sensor console isn't the same as the last detection time in the Azure portal. | | Status | The alert status: New, Active, Closed

    For more information, see Alert statuses and triaging options.| | Source device |The IP address, MAC address, or the name of the device where the traffic that triggered the alert originated. | | Tactics | The MITRE ATT&CK stage. |

Considerations for viewing alerts

Keep the following considerations in mind when viewing alerts:

Filter alerts displayed

For example, while the total number of alerts appears in the alerts summary, you might want more specific information about alert count breakdown, such as the number of alerts with a specific severity, protocol, or site.

Supported grouping options include Engine, Name, Sensor, Severity, and Site.

View details and remediate a specific alert

For more information, see Alert statuses and triaging options.

  • To manage a single alert:alert:

    1. In Defender for IoT in the Azure portal, select the Alerts page on the left, and then select an alert in the grid.
    2. Either on the details pane on the right, or in an alert details page itself, select the new status and/or severity.
  • To manage multiple alerts in bulk:bulk:

    1. In Defender for IoT in the Azure portal, select the Alerts page on the left, and then select the alerts in the grid that you want to modify.
    2. Use the :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/status-icon.png" border="false"::: Change status and/or :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/severity-icon.png" border="false"::: Change severity options in the toolbar to update the status and/or the severity for all the selected alerts.
  • To learn one or more alerts:alerts:

    In Defender for IoT in the Azure portal, select the Alerts page on the left, and then do one of the following:

Access alert PCAP data

You might want to access raw traffic files, also known as packet capture files or PCAP filesfiles, as part of your investigation. If you're a SOC or OT security engineer, access PCAP files directly from the Azure portal to help you investigate faster.

To access raw traffic files for your alert, select Download PCAP in the top-left corner of your alert details page.

Remediate aggregated alert violations

To reduce alert fatigue, Defender for IoT combines multiple instances of the same alert violation with identical parameters into a single alert item, called an aggregated alert, on the Alerts page. You can identify an aggregated alert by the Multiple violations message that appears under the Source device IP. Use the Violations tab to investigate further and the Take action tab to remediate the alerts.underlying alert violations.

  1. On the Alerts page, select an alert in the grid to display more details in the pane on the right.

Next step

[!div class="nextstepaction"] Microsoft Defender for IoT alerts