A category of Azure services for internet of things devices.
Event Timeline entries are not forwarded by Defender for IoT forwarding rules. Forwarding rules on OT sensors send alert information only, based on the minimum alert severity and other conditions configured in the rule.
The documented forwarding behavior is:
- Forwarding rules run only on alerts triggered after the rule is created.
- The payload sent to SIEM/Syslog targets (ArcSight, NetWitness, LogRhythm, FortiSIEM, ServiceNow, generic Syslog) consists of alert fields such as alert title, severity, type, protocol, timestamps, source/destination IPs, and category.
- There is no option in the forwarding rule configuration to include Event Timeline data; only alerts and (optionally, in some integrations) system/alert notifications are supported.
To get Event Timeline–like visibility in downstream systems, configure forwarding rules to send alerts (and system notifications where available) and then use those alert records in the SIEM to approximate the timeline. Direct forwarding of Event Timeline entries themselves is not supported by the forwarding rules described in the available documentation.
References:
- Integrate ArcSight with Microsoft Defender for IoT
- Forward on-premises OT alert information
- Integrate RSA NetWitness with Microsoft Defender for IoT
- Integrate LogRhythm with Microsoft Defender for IoT
- Integrate Fortinet with Microsoft Defender for IoT
- Integrate ServiceNow with Microsoft Defender for IoT (legacy)