You are on page 1of 1

We discussed the issue encountered in the QRadar console regarding the automatic note added to all

offenses. Costin and David said that this problem was addressed to Brindha, but we did not receive any
updates. We will wait until she returns from holiday.

Also, Brindha informed us to make a list of IP addresses that appear from a wrong country in the “Login
from Blacklisted Country” offenses. So far only one IP address has been identified.

Regarding the offenses in which are reported denied network connections to different malicious IP
addresses, Vincent Hamilton reached out to the Firewall team and informed us that the traffic is coming
from a backup Cisco router in Phoenix sending ICMP packets that are dropped by a PAN firewall in
Phoenix. There is no indicator of compromise and the FW team will work to remediate the misleading
logs.

You might also like