|
Scenario: AN environment has dozens of IDS appliances monitoring their network and they are all emitting detection events which I want to collect and map to Detection Finding. Question: how would I identify exactly which IDS appliance was the source of the event? Ideas I explored:
Is there a location that I'm overlooking? or do we need to add a Any guidance would be appreciated. |
Answered by
guy9001
May 26, 2024
Replies: 1 comment 1 reply
|
|
1 reply
Answer selected by
sunilamin
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
metadata.loggershas thedeviceobject inside, I think that could be a good spot if you're looking to add the "logging device" - what do you think?