Skip to content

IP mismatch in Hunt #12936

Answered by dougburks
ben-sec asked this question in 2.4
May 6, 2024 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Here's one possible reason. The default Fetch Limit for the Group Metrics section is 10 so you're only going to see the top 10 IP addresses. The default Fetch Limit for the Events table at the bottom is 100 so you're only going to see 100 events by default. The default search is likely querying thousands of logs or more. So it's quite possible that the 100 logs in the Events table just happen to be more obscure logs with different IP addresses compared to the Group Metrics section. If you click one of the IP addresses in the Group Metrics section and then click Include, then the events in the Events table should show that IP address. For more information, please see:
https://docs.security…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ben-sec
Comment options

Answer selected by ben-sec
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants