Manage "Suspicious IP-ET" Continuous Events
Anonymous
Not applicable
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎04-09-2019 12:32 PM
Hi,
This is linked in part to a previous post:
https://community.extremenetworks.com/extrememanagement-230297/extremeanalytics-suspicious-ip-et-782...
At this time XMC is recording 728,320 alarms of this event, and the events log is getting continuously filed with the messages, all from different IP address.
The XMC help, as does the link above mention an 'IP Reputation' dashboard which I am unable to find?
There log looks like its coming from the fact that suspicious IP addresses are being seen, but without the a Dashboard or means of control that I can find the logs are getting swamped.
Maybe its something that is coming in a future release, current version 8.2.4.42?
Many thanks
This is linked in part to a previous post:
https://community.extremenetworks.com/extrememanagement-230297/extremeanalytics-suspicious-ip-et-782...
At this time XMC is recording 728,320 alarms of this event, and the events log is getting continuously filed with the messages, all from different IP address.
The XMC help, as does the link above mention an 'IP Reputation' dashboard which I am unable to find?
There log looks like its coming from the fact that suspicious IP addresses are being seen, but without the a Dashboard or means of control that I can find the logs are getting swamped.
Maybe its something that is coming in a future release, current version 8.2.4.42?
Many thanks
1 REPLY 1
Anonymous
Not applicable
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎04-09-2019 01:33 PM
I've created this dashboard through the report designer, which I believe gives me the detail in what the Suspicious IP-ET events are:
Pre-built one:
Looks like the IP addresses are clickable but nothing happens. Be good for example that I could create a policy to straight off clicking, say, the high risk endpoints.
Pre-built one:
Looks like the IP addresses are clickable but nothing happens. Be good for example that I could create a policy to straight off clicking, say, the high risk endpoints.
