The add_network_direction
processor attempts to compute the perimeter-based
network direction when given a source and destination IP address and a list of
internal networks.
- add_network_direction:
source: source.ip
destination: destination.ip
target: network.direction
internal_networks: [ private ]
Name | Required | Default | Description |
---|---|---|---|
|
Yes |
Source IP. |
|
|
Yes |
Destination IP. |
|
|
Yes |
Target field where the network direction will be written. |
|
|
Yes |
List of internal networks. The value can contain either CIDR blocks or a list of special values enumerated in the network section of [conditions]. |