We have a new security director and I have been tasked with created a few reports about IP traffic.
The request for for the following:
-Top 20 outbound IPs that are NOT in the DNS cache
-Top 20 outbound IPs by data sent
-Top 20 outbound IPs by connection time
I have been working on a custom report for this, but I'm having trouble editing out the DNS cached IPs - there doesnt seem to be an option. I really just need a way (if possible) to remove cached entries, and just list IPs
I'm not sure you can do this with the PAN. You might need a SIEM for this however if you are referring to the DNS cache of the PAN, you might be out of luck on that. You'll have to get that from the DNS server the PAN is using for lookups.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!