Hi All,
I am trying to build a use-case from the firewall logs wherein if any allowed traffic is observed from any Public IP towards the Network on suspicious ports like SSH, RDP etc , it should trigger an alert. Is there any way through which I can achieve the following through Enterprise security :
If there is allowed connection from any other IP other than the IP in threat intel , alert severity should be low.
If there is allowed connection from threat intel IP, alert severity should be high.