Overview
This collector query Defender for IoT Azure subscriptions quickly and efficiently. Users can ingest all related Defender for IoT alerts into Devo. The user must be forwarding their Defender for IoT data to Azure.
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading ( |
|
Running environments |
|
Populated Devo events |
|
Flattening preprocessing |
|
Allowed source events obfuscation |
|
Data sources
Data source | Description | API endpoint | Collector service name | Devo table | Available from release |
---|---|---|---|---|---|
Defender for IoT - Alerts | Alerts reported by Defender for IoT sensors. |
|
|
|
|
For more information on how the events are parsed, visit our page.
Minimum configuration required for basic pulling
Although this collector supports advanced configuration, the fields required to retrieve data with basic configuration are defined below.
This minimum configuration refers exclusively to those specific parameters of this integration. There are more required parameters related to the generic behavior of the collector. Check setting sections for details.
Setting | Details |
---|---|
| Client ID |
| Client secret |
| Tenant ID |
See the Accepted authentication methods section to verify what settings are required based on the desired authentication method.
Accepted authentication methods
Authentication method | Client ID | Client secret | Tenant ID |
---|---|---|---|
| Required | Required | Required |
Run the collector
Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (Cloud collector), or deploy and host the collector in your own machine using a Docker image (On-premise collector).
Collector services detail
This section is intended to explain how to proceed with specific actions for services.
iot_security_alerts
Collector operations
This section is intended to explain how to proceed with specific operations of this collector.
Change log for v1.0.0
Release | Released on | Release type | Details | Recommendations |
---|---|---|---|---|
| INITIAL RELEASE | Initial release |