2014-06-11 09:43 AM
Good Morning,
We have about 1600 windows servers in multiple domains with the snare client sending to a central syslog server that forwards to one of our log hybrids. I am only seeing around 700 servers getting to the log hybrid. I need to determine which servers are not getting through the firewalls. Is there a way to run a report of DNS names getting to the log hybrid? If I had the domains that are being ingested I could determine which domains are not getting through.
Thanks for any help,
John
2014-06-11 11:23 AM
select device.name.
can you monitor the device ips from logdecoder-stats.
2014-06-12 10:47 AM
Thanks.
How can I run a report to list all IP's?
John
2014-06-12 11:17 PM
yes, you can. select device.ip, don't put any limit.