IP Addresses in IDR

Hi.
I use the main “Search” field in the upper right-hand corner a lot when trying to get more information about a user or asset. Sometimes when searching for an IP address that I found in Log Search or an investigation i get “no results found” in the search field for that IP address which is an internal address to my network. What is the criteria that has to be meant for IDR to create a record for this IP address?

Hope that makes sense.

IDR needs to have attributed this IP address to an asset in order for it to appear

This means it would need to have appeared in Host to IP observations by way of a DHCP/VPN/Insight Agent/AD event source and been successfully mapped to a hostname

David

1 Like