-
Scenario: AN environment has dozens of IDS appliances monitoring their network and they are all emitting detection events which I want to collect and map to Detection Finding. Question: how would I identify exactly which IDS appliance was the source of the event? Ideas I explored:
Is there a location that I'm overlooking? or do we need to add a Any guidance would be appreciated. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
Beta Was this translation helpful? Give feedback.
metadata.loggers
has thedevice
object inside, I think that could be a good spot if you're looking to add the "logging device" - what do you think?