cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Community Team Member

Hi @R.Arrington ,

 

The time mismatch between the threat and traffic logs can happen due to how DNS requests and sinkhole responses are processed. Instead of trying to match exact timestamps, can you try filtering traffic logs by the sinkhole IP as the destination? Do you see reccuring internal IPs around the same time frame? 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
Who rated this post