Navigate to IoT Hub > Your hub > Defender for IoT > Settings > Data Collection.
Under Microsoft Defender for IoT, ensure that Enable Microsoft Defender for IoT is enabled.
Select Save.
Create a Log Analytics workspace
Defender for IoT allows you to store security alerts, recommendations, and raw security data, in your Log Analytics workspace. Log Analytics ingestion in IoT Hub is set to off by default in the Defender for IoT solution. It is possible, to attach Defender for IoT to a Log Analytics workspace, and to store the security data there as well.
There are two types of information stored by default in your Log Analytics workspace by Defender for IoT:
Security alerts.
Recommendations.
You can choose to add storage of an additional information type as raw events.
Note
Storing raw events in Log Analytics carries additional storage costs.
Navigate to IoT Hub > Your hub > Defender for IoT > Settings > Data Collection.
Under the Workspace configuration, switch the Log Analytics toggle to On.
Select a subscription from the drop-down menu.
Select a workspace from the drop-down menu. If you don't already have an existing Log Analytics workspace, you can select Create New Workspace to create a new one.
Verify that the Access to raw security data option is selected.
Select Save.
Every month, the first 5 gigabytes of data ingested, per customer to the Azure Log Analytics service, is free. Every gigabyte of data ingested into your Azure Log Analytics workspace, is retained at no charge for the first 31 days. For more information on pricing, see, Log Analytics pricing.
Enable geolocation and IP address handling
In order to secure your IoT solution, the IP addresses of the incoming, and outgoing connections for your IoT devices, IoT Edge, and IoT Hub(s) are collected and stored by default. This information is essential, and used to detect abnormal connectivity from suspicious IP address sources. For example, when there are attempts made that try to establish connections from an IP address source of a known botnet, or from an IP address source outside your geolocation. The Defender for IoT service, offers the flexibility to enable, and disable the collection of the IP address data at any time.
Discover how to set up and integrate a Log Analytics agent with a workspace in Defender for Cloud using the Azure portal, enhancing security data analysis capabilities.
Microsoft Defender for IoT provides comprehensive threat detection for IoT/OT environments, with multiple deployment options including fully on-premises, cloud-connected, or hybrid.