Get-AzIotSecurityAnalytics
Get IoT security analytics
Syntax
Get-AzIotSecurityAnalytics
-ResourceGroupName <String>
-SolutionName <String>
[-Default]
[-DefaultProfile <IAzureContextContainer>]
[<CommonParameters>]
Description
The Get-AzIotSecurityAnalytics cmdlet returns a set of security analytics of a specific iot security solution
Examples
Example 1
Get-AzIotSecurityAnalytics -ResourceGroupName "MyResourceGroup" -SolutionName "MySolution" -Default
Id: "/subscriptions/XXXXXXXX-XXXX-XXXXX-XXXX-XXXXXXXXXXXX/resourceGroups/MyResourceGroup/providers/Microsoft.Security/iotSecuritySolutions/MySolution/analyticsModels/default"
Name: "default"
Type: "Microsoft.Security/IoTSecuritySolutionAnalyticsModel"
Metrics: {
High": 5
Medium: 200
Low: 102
}
UnhealthyDeviceCount: 1200
DevicesMetrics: [
{
Date: "2019-02-01T00:00:00Z"
DevicesMetrics: {
High: 3
Medium: 15
Low: 70
}
}
{
Date: "2019-02-02T00:00:00Z"
DevicesMetrics: {
High: 3
Medium: 45
Low: 65
}
}
]
TopAlertedDevices: [
{
DeviceId: "id1"
AlertsCount: 200
}
{
DeviceId": "id2"
AlertsCount": 170
}
{
DeviceId": "id3"
AlertsCount": 150
}
]
MostPrevalentDeviceAlerts: [
{
AlertDisplayName: "Custom Alert - number of device to cloud messages in AMQP protocol is not in the allowed range"
ReportedSeverity: "Low"
AlertsCount: 200
}
{
AlertDisplayName: "Custom Alert - execution of a process that is not allowed"
ReportedSeverity: "Medium"
AlertsCount: 170
}
{
AlertDisplayName": "Successful Bruteforce"
ReportedSeverity": "Low"
AlertsCount": 150
}
]
MostPrevalentDeviceRecommendations: [
{
RecommendationDisplayName: "Install the Azure Security of Things Agent"
ReportedSeverity: "Low"
DevicesCount: 200
}
{
RecommendationDisplayName: "High level permissions configured in Edge model twin for Edge module"
ReportedSeverity: "Low"
DevicesCount: 170
}
{
RrecommendationDisplayName: "Same Authentication Credentials used by multiple devices"
ReportedSeverity: "Medium"
DevicesCount: 150
}
]
}
}
Get the deafult IoT Security Analytics for Security Solution "MySolution" in reasource group "MyResourceGroup"
Parameters
-Default
If present, get the default analytics set, otherwise, get the list of all analytics sets.
Type: | SwitchParameter |
Position: | Named |
Default value: | None |
Required: | False |
Accept pipeline input: | False |
Accept wildcard characters: | False |
-DefaultProfile
The credentials, account, tenant, and subscription used for communication with Azure.
Type: | IAzureContextContainer |
Aliases: | AzContext, AzureRmContext, AzureCredential |
Position: | Named |
Default value: | None |
Required: | False |
Accept pipeline input: | False |
Accept wildcard characters: | False |
-ResourceGroupName
Resource group name.
Type: | String |
Position: | Named |
Default value: | None |
Required: | True |
Accept pipeline input: | False |
Accept wildcard characters: | False |
-SolutionName
Solution name
Type: | String |
Position: | Named |
Default value: | None |
Required: | True |
Accept pipeline input: | False |
Accept wildcard characters: | False |
Inputs
None