Hi,
I'm new to Elastic Security.
Network events are logged with destination IP address. Is there any way it can be translated to hostname/FQDN.?
Is there any setting can be done for DNS resolution.?
I'm currently running trial instance in GCP.
-- Thanks & Regards
Don't believe there's a way to do it in elastic or in a pipeline currently, this is something you would want to do in Logstash - Dns filter plugin | Logstash Reference [7.13] | Elastic
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.