Municipal IoT Security Audit Log

This dataset provides detailed logs of IoT device security events across municipal infrastructure, including device details, event types, severity, compliance status, and remediation actions. It enables public sector teams to monitor vulnerabilities, benchmark security performance, and support regulatory compliance, making it a valuable resource for smart city cybersecurity and resilience initiatives.

  • last updated 24 Jan 2026
  • by GoMask
The brief that made it

Benchmarking IoT security performance across municipalities

Sample rows

preview · 8 of 121 rows · all 20 columns
event_idstringevent_typestringcompliance_flagbooleandevice_location_statestringevent_timestampdatetimedevice_idstringdevice_typestringdevice_location_streetstringdevice_location_citystringdevice_location_postal_codestringdevice_location_countrystringmunicipality_idstringmunicipality_namestringevent_severitystringevent_statusstringreported_bystringremediation_actionstringcompliance_standardstringvulnerability_idstringevent_descriptionstring
A9B3XZ-12unauthorized-accesstrueIL2022-02-28T09:13:44ZDEV-001sensor120 Maple StSpringfield62701USMUNI-001SpringfieldmediumopensystemblankNISTblankUnusual login detected on sensor device.
KJL-0034-XXmalware-detectedtrueCA2023-11-15T19:04:12ZDEV-002camera503 Oak AveRiverside92501USMUNI-002RiversidehighinvestigatingSOCblankISO-27001blankMalware signature found in camera firmware.
DEV-003-LOGfirmware-updatefalseTX2024-05-29T16:33:21ZDEV-003meterblankFairview75069USMUNI-003FairviewlowresolvedautomationUpdate verified and completed.noneblankRoutine firmware update applied to smart meter.
9AF1-004L-YYvulnerability-detectedtrueYT2023-12-25T21:07:00ZDEV-004environmental-monitor88 Snow RdWhitehorseY1A4N1CAMUNI-004Whitehorsecriticalopensecurity-teamblankNISTCVE-2023-5001Critical vulnerability detected in air quality monitor.
MUNI-005-LOG1configuration-changefalseOH2022-07-04T11:24:38ZDEV-005traffic-light101 Main AveCenterville45459USMUNI-005CentervillemediumresolvedadminSettings verified.noneblankTraffic light configuration updated.
DEV-006-4421network-anomalytrueSC2023-09-09T14:20:11ZDEV-006sensor25 Elm StGreenville29601USMUNI-006GreenvillehighopenNIDSblankGDPRblankUnexpected traffic spike detected on sensor network.
BATCH1-007firmware-updatefalseTX2021-04-15T06:10:55ZDEV-007meterblankLakeview75070USMUNI-007LakeviewmediumresolvedsystemUpdate completed.noneblankPower meter updated to v3.4.
T-008-XXnetwork-anomalyfalseTN2023-01-01T03:03:03ZDEV-008sensor13 Pine LnKingsport37660USMUNI-008KingsportmediuminvestigatingIDSblanknoneblankSensor experienced packet loss during New Year.

What the 121 rows show

from the 121-row sample

Vulnerability-detected (event type) stands out: 25 of its 25 rows have compliance_flag = true, against 23 of 96 for the rest.

  • 40%compliance_flag = true
  • 4event severities
  • 4event statuses
  • 6device types
  • 6compliance standards
  • 12reported_by values
Compliance flag rate by event_typecompliance_flag = true
0%50%100%31%unau…5 of …0%firm…0 of …100%vuln…25 of…100%malw…14 of…0%conf…0 of …21%netw…4 of …0%other0 of 8
device_location_state91 rows with a value · 30 left blank
  1. TX11
  2. CA7
  3. ON5
  4. AZ5
  5. OH4
  6. NY4
  7. WI3
  8. BC3
  9. NE3
  10. MI3
20 columns by typefrom the column list below
  • string 18
  • datetime 1
  • boolean 1

Columns

20 columns in three groups
blueprint · 20 columns
columntypedescriptionexample
Text 18 columns
event_idstringUnique identifier for each security event log entryuniqueA9B3XZ-12
device_idstringUnique identifier for the IoT device involved in the eventDEV-001
device_typestringType or category of the IoT device (e.g., sensor, camera, traffic light)6 valuessensor
device_location_streetstringStreet address where the device is physically locatedoptional120 Maple St
device_location_citystringCity where the device is locatedSpringfield
device_location_statestringState or province where the device is locatedIL
device_location_postal_codestringPostal code for the device's locationoptional62701
device_location_countrystringCountry where the device is locatedUS
municipality_idstringUnique identifier for the municipality responsible for the deviceMUNI-001
municipality_namestringName of the municipalitySpringfield
event_typestringType of security event (e.g., unauthorized access, firmware update, vulnerability detected)7 valuesunauthorized-access
event_severitystringSeverity level of the eventlow · medium · high · criticalmedium
event_descriptionstringDetailed description of the security eventoptionalMeter firmware updated.
event_statusstringCurrent status of the event (e.g., open, investigating, resolved, false positive)open · investigating · resolved · false-positiveopen
reported_bystringName or identifier of the person/system that reported the event12 values · optionalsystem
remediation_actionstringDescription of actions taken to remediate the eventoptionalSettings verified.
compliance_standardstringName of the compliance standard involved (e.g., NIST, ISO 27001, GDPR)6 values · optionalNIST
vulnerability_idstringIdentifier for the vulnerability (if applicable, e.g., CVE number)optionalCVE-2023-5001
Dates and times 1 column
event_timestampdatetimeDate and time when the security event occurred2022-02-28T09:13:44Z
True or false 1 column
compliance_flagbooleanIndicates whether the event relates to a compliance requirementtrue

Use it for

  • compliance flag40%48 of 121 rowscompliance flag by ev…31%unau…0%firm…100%vuln…100%malw…

    A government dashboard

    The compliance_flag rate, compliance_flag by event_type and a breakdown of device_location_state. Excel, Power BI or Tableau.

  • Why do 48 of 121 rows have compliance_flag = true?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable events with event_timestamp, device_id and device_type to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 20 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset121 rows20 columns
Yours10,000 rows20 columnsdevice_location_street: UK only

blueprint · municipal-iot-security-audit-log

Behind this dataset

Same schema. As many rows as you need.

These 121 rows came out of a blueprint — 20 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Each row represents one IoT security event on a unique device.
  • Include device type, event severity, and timestamp for every entry.
  • Capture location (facility/building) and responsible department.
  • Flag events related to compliance breaches or failed updates.
  • Only include events from devices connected to municipal networks.
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
municipal-iot-security-audit-log

What should your data show?

Preview 20 rows free
No signup. No card.