Skip to content
Discussion options

You must be logged in to vote

If you have an internal web service that can resolve IP addresses to names, then you could add that web service as a custom action:
https://docs.securityonion.net/en/2.3/soc-customization.html#action-menu

Alternatively, you might be able to modify the ingest pipeline to perform the DNS lookups. However, please note that can have serious performance implications for your ingest pipeline.

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants