IoT Endpoint Anomaly Detection Logs

This dataset provides detailed, time-stamped logs of events and anomalies detected across remote IoT endpoints, including device identifiers, event types, severity scores, diagnostics, and compliance status. It is optimized for cybersecurity teams and AI/ML model training, supporting robust threat detection, incident response, and fleet management for edge computing environments.

  • last updated 19 Jan 2026
  • by GoMask
The brief that made it

Real-time monitoring and detection of security anomalies in IoT fleets

Sample rows

preview · 8 of 110 rows · all 14 columns
log_idstringevent_typestringseverity_scorefloatanomaly_flaggedbooleananomaly_typestringdevice_idstringdevice_typestringdevice_locationstringevent_timestampdatetimeevent_descriptionstringdiagnostic_summarystringresponse_actionstringcompliance_statusstringfleet_idstring
A9kL2m8QxZheartbeatblankfalseblankdev-1023AxsensorBuilding B, Floor 12024-05-09T08:24:17ZDevice sent routine heartbeat signal.Signal strength within normal range.blankcompliantfleet-east-01
C2pZ6wL4Nqanomaly0.74trueunauthorized_accesscam-2048BvcameraRemote Site 32024-05-09T09:01:45ZUnexpected movement detected outside scheduled hours.AI model flagged motion pattern as suspicious.alert_sentnon_compliantfleet-north-02
Q8rB5eJ1Tsdata_transmissionblankfalseblanksens-9987TrsensorWarehouse C, Gate 42024-05-09T10:15:29ZTemperature data transmitted to cloud.No data loss detected.blankcompliantfleet-west-03
F7sH4kW5Lmfirmware_updateblankfalseblankgtw-5111UxgatewayBuilding A, Floor 22024-05-09T11:03:13ZFirmware updated to v2.1.4.Update completed successfully.blankcompliantfleet-central-04
K5vM1xP8Rtloginblankfalseblankcam-2048BvcameraRemote Site 32024-05-09T12:44:22ZAdministrator login successful.User authenticated via 2FA.blankcompliantfleet-north-02
S3xT7rV2Ypanomaly0.62trueabnormal_trafficsens-9987TrsensorWarehouse C, Gate 42024-05-09T13:20:41ZTemperature spike detected.Model detected rapid sensor value change.alert_sentcompliantfleet-west-03
L2qD8vN6Zmheartbeatblankfalseblankgtw-5111UxgatewayBuilding A, Floor 22024-05-09T14:37:16ZDevice responded to status poll.No issues detected.blankcompliantfleet-central-04
E9gJ3fC7Qwconfiguration_changeblankfalseblankdev-1023AxsensorBuilding B, Floor 12024-05-09T15:50:08ZReporting interval changed from 5min to 10min.Change authorized by admin user.blankcompliantfleet-east-01

What the 110 rows show

from the 110-row sample

Anomaly (event type) stands out: 33 of its 33 rows have anomaly_flagged = true, against 1 of 77 for the rest.

  • 31%anomaly_flagged = true
  • 0.77median severity_score
  • 3response actions
  • 3compliance statuses
  • 4device types
  • 18device locations
Anomaly flagged rate by event_typeanomaly_flagged = true
0%50%100%8%login1 of 120%firmw…0 of 110%data_…0 of 18100%anoma…33 of …0%confi…0 of 90%heart…0 of 27
severity_score34 rows, in bands of 0.1
05101387960.40.71severity_score →

Median 0.77, from 0.41 to 0.97.

anomaly_type34 rows with a value · 76 left blank
  1. abnormal_traffic10
  2. device_failure8
  3. unauthorized_access7
  4. policy_violation4
  5. malware_detected4
  6. other1
14 columns by typefrom the column list below
  • string 11
  • float 1
  • datetime 1
  • boolean 1

Columns

14 columns in four groups
blueprint · 14 columns
columntypedescriptionexample
Text 11 columns
log_idstringUnique identifier for each anomaly detection log entryuniqueA9kL2m8QxZ
device_idstringUnique identifier for the IoT endpoint devicedev-1023Ax
device_typestringType or model of the IoT device (e.g., sensor, camera, gateway)4 typessensor
device_locationstringPhysical or logical location of the device (e.g., 'Building A, Floor 2', 'Remote Site 12')optionalBuilding B, Floor 1
event_typestringType of event detected (e.g., login, firmware_update, data_transmission, anomaly)7 valuesheartbeat
event_descriptionstringDetailed description of the eventoptionalImage data uploaded.
anomaly_typestringType of anomaly detected (e.g., unauthorized_access, abnormal_traffic, device_failure)6 values · optionalunauthorized_access
diagnostic_summarystringSummary of diagnostics or AI/ML model output for the eventoptionalNo data loss detected.
response_actionstringAction taken in response to the event or anomaly (e.g., alert_sent, device_isolated, no_action)5 values · optionalalert_sent
compliance_statusstringIndicates if the device/event is compliant with security policies (e.g., compliant, non_compliant, unknown)compliant · non_compliant · unknown · optionalcompliant
fleet_idstringIdentifier for the group or fleet to which the device belongsoptionalfleet-east-01
Numbers 1 column
severity_scorefloatNumerical score representing the severity of the anomaly (0.0-1.0)0 to 1 · optional0.74
Dates and times 1 column
event_timestampdatetimeDate and time when the event was logged2024-05-09T08:24:17Z
True or false 1 column
anomaly_flaggedbooleanIndicates if the event was flagged as an anomalyfalse

Use it for

  • anomaly flagged31%34 of 110 rowsanomaly flagged by ev…8%login0%firm…0%data…100%anom…

    A technology dashboard

    The anomaly_flagged rate, severity_score by event_type and a breakdown of anomaly_type. Excel, Power BI or Tableau.

  • Why do 34 of 110 rows have anomaly_flagged = true?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable logs with device_id, device_type and device_location to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 14 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset110 rows14 columns
Yours10,000 rows14 columnsdevice_location: UK only

blueprint · iot-endpoint-anomaly-detection-logs

Behind this dataset

Same schema. As many rows as you need.

These 110 rows came out of a blueprint — 14 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Each log entry must include device ID, timestamp, event type, and anomaly flag
  • Severity scores are assigned on a scale of 1-10 based on ML-driven risk assessment
  • Anomalies are only flagged when deviation exceeds established operational baseline
  • Diagnostic summary must list probable source (firmware, network, sensor) for each anomaly
  • No device can have more than 3 critical anomalies per 24 hours
  • Only endpoints with edge connectivity status 'active' are monitored
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
iot-endpoint-anomaly-detection-logs

What should your data show?

Preview 20 rows free
No signup. No card.