You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, I am a new Malcolm user and I have a question about the log enrichment. For the source and destination of logs, is Malcolm able to find out the device type (i.e. PLC, PC, workstation, etc)? I uploaded a pcap file to Malcolm earlier but didn't find much log information about the device type.
Thanks for your help!
The text was updated successfully, but these errors were encountered:
You're correct, right now Malcolm doesn't have much in the way of determining the type of host detected in network traffic. There are a few ways you could infer that information, sometimes, but it depends on the type of traffic and type of device whether or not it will be very successful:
you can look at the device manufacturer (the OUI fields), for example in the Connections dashboard
you can check out the Software dashboard to look for names and versions of software that might indicate the type of device to you
for ICS devices, you can check out the ICS Best Guess dashboard which may provide some guesses
Improved asset identification/discovery/management is on Malcolm's future roadmap and will be worked on over the next several months. Thanks for the request.
Hi, I am a new Malcolm user and I have a question about the log enrichment. For the source and destination of logs, is Malcolm able to find out the device type (i.e. PLC, PC, workstation, etc)? I uploaded a pcap file to Malcolm earlier but didn't find much log information about the device type.
Thanks for your help!
The text was updated successfully, but these errors were encountered: