Uploaded image for project: 'Red Hat Advanced Cluster Security'
  1. Red Hat Advanced Cluster Security
  2. ROX-28546

Add External IP details to Anomalous Flows violation messages

    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • 0

      Customer problems: 

      As a customer, I want to be able to see the external IP addresses of the entity that has caused an Unauthorized Network Flow policy alert so I can identify better the source and investigate if it could come from a malicious actor. For example, I could use that IP to check the logs of my perimeter defense tool and correlate the data.

      Acceptance Criteria:

      Unexpected Network Flows should include an IP address if External IPs are enabled for the cluster and the traffic is to/from an external entity.

      Example: replace `Destination/Source: External Entities` with the IP address.

              rh-ee-masimonm Maria Simon Marcos
              rcochran@redhat.com Robby Cochran
              Maria Simon Marcos Maria Simon Marcos
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: