I'd like to be able to do that as well. I've attempted to create a UDS with fixed-field values for the IP addresses that I needed to monitor but there is a limitation of ten values which didn't cover my list. You can increase the limitation to 50 but I don't know if that has performance consequences or not. I don't know why the limitation is so low. We used to watch large ranges of IP addresses with a competing sensor without any problems.
Thanks for the response, Bob. Yes, I know of 2 of their competitors in IPS/IDS that make this sort of tracing comparatively easy for ranges of IP addresses if not CIDR-defined ranges. The MSM monitors more networks than we have sniffers or sniffer access.