0 Replies Latest reply on Jan 25, 2016 9:38 AM by layer0

    McAfee SIEM Domain to IP




      I have a situation. I have to correlate events from a data source that generate data based in domain name, and a data source that only see Source IP or destination IP, for example a Firewall.


      For example,

      In Data Source 1, i see an event with Field Destination_Hostname: example.com

      In Data Source 2. I see events with source IP:


      I want to correlate this two events, Is it possible to transform example.com to and use it in a correlation rule?.