cancel
Showing results for 
Search instead for 
Did you mean: 
SDee87
Level 7
Report Inappropriate Content
Message 1 of 2

Correlation Entry for "Same Source IP"

I want to create several correlation rules but currently stuck at a single point.

 

Let's say I want to do the following log,

Same Source IP, Same Destination IP's, Different Usernames --> Log

 

What would the statement be for "Same" & "Different" when it comes to Source IP or Source User?

1 Reply
DavA
Level 9
Report Inappropriate Content
Message 2 of 2

Re: Correlation Entry for "Same Source IP"

Hi,

do's anyone have a answer?

I need even something similar.

Thank's

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator