Parse Industrial OT Device Files
Table of Contents
Expand all | Collapse all
-
- Firewall and PAN-OS Support of IoT Security
- IoT Security Prerequisites
- Onboard IoT Security
- Onboard IoT Security on VM-Series with Software NGFW Credits
-
- DHCP Data Collection by Traffic Type
- Firewall Deployment Options for IoT Security
- Configure a Pre-PAN-OS 10.0 Firewall with a DHCP Server
- Configure a Pre-PAN-OS 10.0 Firewall for a Local DHCP Server
- Use a Tap Interface for DHCP Visibility
- Use a Virtual Wire Interface for DHCP Visibility
- Use SNMP Network Discovery to Learn about Devices from Switches
- Use Network Discovery Polling to Discover Devices
- Use ERSPAN to Send Mirrored Traffic through GRE Tunnels
- Use DHCP Server Logs to Increase Device Visibility
- Plan for Scaling when Your Firewall Serves DHCP
- Prepare Your Firewall for IoT Security
- Configure Policies for Log Forwarding
- Control Allowed Traffic for Onboarding Devices
- Support Isolated Network Segments
- IoT Security Integration with Prisma Access
- IoT Security Licenses
- Offboard IoT Security Subscriptions
-
- Introduction to IoT Security
- IoT Security Integration with Next-generation Firewalls
- IoT Security Portal
- Vertical-themed Portals
- Device-to-Site Mapping
- Sites and Site Groups
- Networks
- Network Segments Configuration
- Reports
- IoT Security Integration Status with Firewalls
- IoT Security Integration Status with Prisma Access
- Data Quality Diagnostics
- Authorize On-demand PCAP
- IoT Security Integrations with Third-party Products
- IoT Security and FedRAMP
Parse Industrial OT Device Files
Add industrial OT device files, such as PLC controller configuration,
program, and inventory files, to IoT Security to enrich your asset
inventory.
PLC controller configuration, program, and inventory files,
referred to as device files, control and manage machinery and
processes for industrial OT devices. Because device files define
parameters and customize industrial devices to suit operational
requirements, they contain detailed asset information. This can
include information such as the name, model, vendor, and
firmware of devices, as well as information about hardware
components and downstream devices. In particular, device files
can contain information for industrial OT equipment that operate
in isolated network segments. If firewalls don't see traffic
from those industrial OT devices, IoT Security can't learn
about those assets from passive traffic monitoring.
Use device files along with IoT Security features, such as
Network Discovery Polling
and third-party integrations
to enrich your asset inventory. To use device files to augment
your IoT Security asset inventory, you need to have an
Industrial OT subscription. On an Industrial OT
IoT Security tenant, view and add devices files on the
Device Files page under AssetsDevice Files.
On the Device Files page, the Overview section shows a summary
of files added, devices learned, and devices enriched from
device files in the past 30 days. Below the Overview section,
the Parsing History table displays all device files uploaded to
your IoT Security tenant. This table includes information
such as the parsing history of each file, and how many devices
were updated or how many devices were missing critical
information, such as MAC and IP address, in each file. You can
also download previously uploaded device files from the table.
When adding a device file, you need to choose a site association
before uploading a file. The site association helps avoid
potential conflicts with overlapping IP addresses, and it serves
as the site assignment for any new devices learned. You can
upload only one file at a time, and each file can't exceed
100 MB in size. IoT Security supports the following device
file types for parsing:
- Rockwell AssetCentre (.raai)
- Studio 5000 Logix Designer (.l5x)
- Unity Application Exchange File (.xef)
- Siemens TIA Portal (.zip file containing a Project Library File (.plf) and an Index File (.idx))
Upload Device Files
You can only upload one device file at a time. Verify the
parsed content and submit a device file before adding
another device file.
- Login in to your Industrial OT Security portal and navigate to AssetsDevice Files.In the Parsing History table, click on the Upload icon to open the File Parsing side panel.Select the site to associate your device file with.Drag and drop your device file into the Select Files box, or Browse your folders and select the device file to upload.Review the result of the parsed device file.After IoT Security parses a file, it displays a table with the parsed output. The table lists the names of all devices discovered from the device file, as well as whether those devices are new or if they match to an existing device in the IoT Security assets inventory.When a device matches an existing device in IoT Security, you can click on the Device Name field to open up the corresponding Device Details page in a new tab or window. After you submit the device file, the data from the device file will supplement the information on that existing device identity.If the Parsing Output field says Additional Info Required, then IoT Security can't determine if the device is new or if it matches an existing device. Click on Additional Info Required to add an IP address and a MAC address. A device that has an IP address but no MAC address will be created as a static IP address. If you don't want to add the information right away, you can submit the device file first and update the information from the Parsing History table later.After verifying the results of the parsed device file, Submit the file to add the devices and device information to IoT Security.After submitting the device file, you can view the submitted device file in the Parsing History table.
Update Devices Missing Critical Information
When viewing the Parsing History table, some rows may have a value under the field Devices Missing Critical Information. This field indicates the number of devices in that file that are missing an IP address and a MAC address. Update the devices with this information to help IoT Security determine if those devices are new or if they match existing devices in the asset inventory.- Click on the number in the Devices Missing Critical Information field for a device file.This brings up the File Parsing Side panel, where you can review the list of devices that are missing an IP address and a MAC address.For each device, click Additional Info Required in the Parsing Output field to bring up the Device Attributes pop-up.Enter the IP Address for the device.Optional Enter the MAC Address for the device.Apply the updates.Continue updating all devices that are missing critical information, and then Submit the changes after you're done.
Download Past Device Files
- Navigate to AssetsDevice Files and view the Parsing History table.Select the check box next to the device files that you want to download.Download the device files.