0 Replies Latest reply on Jan 25, 2016 9:38 AM by layer0

    McAfee SIEM Domain to IP

    layer0

      Hello

       

      I have a situation. I have to correlate events from a data source that generate data based in domain name, and a data source that only see Source IP or destination IP, for example a Firewall.

       

      For example,

      In Data Source 1, i see an event with Field Destination_Hostname: example.com

      In Data Source 2. I see events with source IP: 93.184.216.34

       

      I want to correlate this two events, Is it possible to transform example.com to 93.184.216.34 and use it in a correlation rule?.

       

      Thnaks.