-
Can Zeek, send an alert if a new device is shows up that's not normal? Let's say you've run Malcolm for 60 days and it's discovered 30 devices. if a new deivce "x" appears that isn't an ip that's "recgnized" or normally observed, can Zeek send an alert about the device? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Hi, great question. At the moment we don't have a way to do that, but I've created an issue (#573) to do just that, as it's a great suggestion. In the meantime, there's a few things you can do with visualizations to sort of approximate that:
Anyway, as I said, I've logged that issue to flag new IPs as such. Thanks for the suggestion. |
Beta Was this translation helpful? Give feedback.
Hi, great question. At the moment we don't have a way to do that, but I've created an issue (#573) to do just that, as it's a great suggestion. In the meantime, there's a few things you can do with visualizations to sort of approximate that: