Resolve Known Networks
To resolve a Known Network, a search is conducted for networks assigned to the Log Source Host Entity in the following order until the search is resolved.
- If the Log Source Host Entity is a child entity:
- Search for networks within the Log Source Host Root Entity.
- Search for networks within other child Entities within the Log Source Host Root Entity.
- If the Log Source Host Entity is a root Entity, search for networks within any child Entities within Log Source Host Entity. This must resolve to a single network. If the search returns more than one network, it goes to Step 5.
- If there is a public IP Address, search other Root Entities, but not their child Entities. This must resolve to a single Host. If the search returns more than one Host, it goes to Step 5.
- Search for network within the Global Entity.
- Known network is not resolved.
Origin and Impacted Network are not saved to the database. The values are determined at run-time.