-
Didn't see an "Issues" at UTMStackCorrelationRules So just wanted to note, at: save: The ip.0 should be destination maybe? Source of the brute force in the log below was ...* (port *****ssh2), so sourceIP should be parsed out of that I think. Just seems to me that destination is the host machine for the agent here, dunno. From log: logx.linux.host.ip.0 logx.linux.host.ip.1 logx.linux.host.ip.2 logx.linux.host.ip.3 logx.linux.host.mac.0 Thanks! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hi @global-H, some of the origins of logs have changed their basic structure, so we will perform rule updates in the future |
Beta Was this translation helpful? Give feedback.
Hi @global-H, some of the origins of logs have changed their basic structure, so we will perform rule updates in the future