Microsoft Defender for IoT
Identity protection

View and Manage Alerts on your OT Sensor

In brief

The page title and metadata were updated, and alert-viewing, management, and export instructions were reformatted with clearer step numbering and wording.

What Defender admins need to know

Administrators will see a more consistent, easier-to-follow reference when viewing or exporting OT alerts. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Sign into your OT sensor console and select the Alerts page on the left.

    By default, the following details are shown in the grid:

    Name Description
    Severity A predefined alert severity assigned by the sensor that you can modify as needed, including: Critical, Major, Minor, Warning.
    Name The alert title
    Engine The Defender for IoT detection engine that detected the activity and triggered the alert.
    Last detection The last time the alert was detected.

    - If an alert's status is New, and the same traffic is seen again, the Last detection time is updated for the same alert.
    - If the alert's status is Closed and traffic is seen again, the Last detection time is not updated, and a new alert is triggered.

    Note: While the sensor console displays an alert's Last detection field in real-time, Defender for IoT in the Azure portal may take up to one hour to display the updated time. This display delay explains a scenario where the last detection time in the sensor console isn't the same as the last detection time in the Azure portal.
    Status The alert status: New, Active, Closed

    For more information, see Alert statuses and triaging options.
    Source Device The source device IP address, MAC, or device name.
    Id The unique alert ID, aligned with the ID on the Azure portal.

    Note: If the alert was merged with other alerts from sensors that detected the same alert, the Azure portal displays the alert ID of the first sensor that generated the alerts.
    1. To view more details, select the :::image type="icon" source="media/how-to-manage-device-inventory-on-the-cloud/edit-columns-icon.png" border="false"::: Edit Columns button.

    2. In the Edit Columns pane on the right, select Add Column and any of the following extra columns:

      Name Description
      Destination Device The destination device IP address.
      First detection The first time the alert activity was detected.
      ID The alert ID.
      Last activity The last time the alert was changed, including manual updates for severity or status, or automated changes for device updates or device/alert de-duplication

Filter alerts displayed

For more information, see Alert statuses and triaging options.

  • To manage alert status:status:

    1. Sign into your OT sensor console and select the Alerts page on the left.

      The :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/status-icon.png" border="false"::: Status option is also available on the alert details page.

  • To learn one or more alerts:alerts:

    Sign into your OT sensor console and select the Alerts page on the left, and then do one of the following:

    • Select one or more learnable alerts in the grid and then select :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/learn-icon.png" border="false"::: Learn in the toolbar.
    • On an alert details page, in the Take Action tab, select Learn.
  • To mute an alert:alert:

    1. Sign into your OT sensor console and select the Alerts page on the left.
    2. Locate the alert you want to mute and open its alert details page.
    3. On the Take action tab, toggle on the Alert mute option.
  • To unlearn or unmute an alert:alert:

    1. Sign into your OT sensor console and select the Alerts page on the left.
    2. Locate the alert you've learned or muted and open its alert details page.
  • Export alerts to a CSV file from the main Alerts page. Export alerts one at a time or in bulk.

  • Export alerts to a PDF file one at a time only, either from the main Alerts page or an alert details page.

To export alerts to a CSV file:file:

  1. Sign into your OT sensor console and select the Alerts page on the left.

  2. In the toolbar above the grid, select Export to CSV.

The file is generated, and you're prompted to open or save itthe file locally.

To export an alert to a PDF file:file:

Sign into your OT sensor console and select the Alerts page on the left, and then do one of the following:

  • On the Alerts page, select an alert and then select Export to PDF from the toolbar above the grid.
  • On an alerts details page, select Export to PDF.

The file is generated, and you're prompted to save itthe file locally.

Add alert comments

Next step

[!div class="nextstepaction"] Data retention across Microsoft Defender for IoT