Threat Intelligence Alert Source IP Threat Indicated
Threat Intelligence Alert - Source IP Threat Indicated
Configuration
query
src_ip_threat_indicated:true AND threat_indicated:true NOT filter_action:block NOT fw_action:drop NOT fw_action:NA
config
Key | Value — | — type | aggregation-v1 query | src_ip_threat_indicated:true AND threat_indicated:true NOT filter_action:block NOT fw_action:drop NOT fw_action:NA streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000
Threat Intelligence Alert Source IP Threat Indicated
Event source IP address is listed on one of more blocklists as having an IOC - Indication of compromise.
notes
Last modified
December 31, 1969