Top 20 Outbound IP Report

Reply
Highlighted
L0 Member

Top 20 Outbound IP Report

We have a new security director and I have been tasked with created a few reports about IP traffic. 

The request for for the following:

-Top 20 outbound IPs that are NOT in the DNS cache

-Top 20 outbound IPs by data sent

-Top 20 outbound IPs by connection time

 

I have been working on a custom report for this, but I'm having trouble editing out the DNS cached IPs - there doesnt seem to be an option. I really just need a way (if possible) to remove cached entries, and just list IPs

 

Thanks

L7 Applicator

Re: Top 20 Outbound IP Report

Hello,

I'm not sure you can do this with the PAN. You might need a SIEM for this however if you are referring to the DNS cache of the PAN, you might be out of luck on that. You'll have to get that from the DNS server the PAN is using for lookups.

 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!