Open DGabri opened 1 week ago
The blacklists timeseries works, the only problem is that it's an hits per second metric, so if you do not have enough blacklisted flows, you are not going to see nothing due to the low hit rate
Healthy networks have very few blacklist hits, hence you need to multiply the hits so that they are non-zero. Possible workarounds include hits/min
I have alerts regarding blacklisted client and server contact made by an IP from IPsum Threat Intelligence Feed but in the timeseries I do not see any hit.