
<image.png>Thanks,Alessandro--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAHQ-h5DRQ-8-Z6bp%2BA-%3Ds0ytpw9J35jjYPdESPcKLLMb53tLkg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/12F2E999-F726-495B-ACAF-486C63BC4030%40wazuh.com.
2016 May 11 15:32:40 WinEvtLog: Microsoft-Windows-Sysmon/Operational: INFORMATION(3): Microsoft-Windows-Sysmon: SYSTEM: NT AUTHORITY: server.anonymous.loca: Network connection detected: UtcTime: 2016-05-11 19:32:40.006 ProcessGuid: {AB6C4F98-86DB-5733-0000-001068070100} ProcessId: 296 Image: C:\Windows\System32\svchost.exe User: NT AUTHORITY\NETWORK SERVICE Protocol: udp Initiated: false SourceIsIpv6: false SourceIp: ###.###.###.### SourceHostname: server.anonymous.local SourcePort: 54796 SourcePortName: DestinationIsIpv6: false DestinationIp: 208.67.222.222 DestinationHostname: resolver1.opendns.com DestinationPort: 53 DestinationPortName: domain

To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAHQ-h5C3hswAvBp_Xg-zKJ0P-YrH%2BdggKFEgHSbdEHo72kxnDQ%40mail.gmail.com.
That probably won't work, unless you define to "geoip" filters. See here the documentation:Only requirement is that the source field needs to be an IP address.The question is if it really makes sense to do geolocation of destination IP addresses. Typically attackers will appear as source IP in your logs, not as destination. That is why default we use "srcip". Are those destination IP addresses yours?I hope it helps,Santiago.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAHQ-h5DRQ-8-Z6bp%2BA-%3Ds0ytpw9J35jjYPdESPcKLLMb53tLkg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/f242b807-a8d1-428d-82a3-7db738f4ab3c%40googlegroups.com.