cancel
Showing results for 
Search instead for 
Did you mean: 

Who Me Too'd this topic

Need stdlib.aggregatorIPv4Generic to provide single IPs instead of IP ranges

L0 Member

Hello all,

 

I am trying to use Minemeld in a setup with Microsoft Sentinel (Microsoft Graph). 

 

I am encountering an issue with entities of type IP, as they are getting  in my log analytics space as IP ranges, mentioned in the "ExternalIndicatorID" along with the word IPv4. I cannot process that and I need single IP alone in another column, like NetworkIP.

 

Is there any way to change the processor to provide single IPs instead of ranges?

 

Thank you.

Who Me Too'd this topic