Top 20 Outbound IP Report

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Top 20 Outbound IP Report

L0 Member

We have a new security director and I have been tasked with created a few reports about IP traffic. 

The request for for the following:

-Top 20 outbound IPs that are NOT in the DNS cache

-Top 20 outbound IPs by data sent

-Top 20 outbound IPs by connection time

 

I have been working on a custom report for this, but I'm having trouble editing out the DNS cached IPs - there doesnt seem to be an option. I really just need a way (if possible) to remove cached entries, and just list IPs

 

Thanks

1 REPLY 1

Cyber Elite
Cyber Elite

Hello,

I'm not sure you can do this with the PAN. You might need a SIEM for this however if you are referring to the DNS cache of the PAN, you might be out of luck on that. You'll have to get that from the DNS server the PAN is using for lookups.

 

Regards,

  • 2907 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!