FIM in defender not showing file changes for newly created file after 3 days also.

Disha Bodade 65 Reputation points
2024-04-30T06:15:50.83+00:00

Team,

I have enabled FIM on one of the Resource Group it has created one default Log Analytics Workspace, DCR rule. We executed a script that will create test file on all VM's in /etc and C:\windows\system32 directory.

But those changes are not yet reflected in Defender->workload protection->FIM.

Also I don't see events generated in ConfigurationChange table in log Analytics workspace.

Not sure what could the issue.

I have enabled those directory monitoring in FIM settings as well.

Thanks,

Disha

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
{count} votes