Question
FortiSIEM: Facilitating investigation by ensuring the traceability of dynamic IP addresses
Dynamic IP addresses change regularly, making it difficult to identify the host associated with an IP address detected at any given time during incident investigations.
Is there anyone who can give me a solution?,
In my opinion, I think we can create a correlation rule that associates DHCP log events with assigned IP addresses to help maintain a correspondence between dynamic IP addresses and hosts, or use Lookup Tables to keep track of the history of assignments.
Thanks,
