I have searched for prior discussion on this, without any positive hits, but there are only 24 hours in each day...
The Port Scan Notification feature is certainly useful, but not nearly as useful as it would be if the notification included at least the target protocol/port.
I recently inserted a robust, full-featured firewall appliance in my network -- properly configured (I've been at this for a minute or two...), and I now see Port Scan Notifications originating from the new firewall appliance. I'd love to correlate this with the activity and flow log from my firewall, but alas, hard to do if I don't know what protocol/port was being "scanned".
I won't ask if it is possible for the developers to include the target protocol/port in Port Scan Notifications (because it is...), but does anyone know of any secret portal where BD stores this information, or if it even does? Is that level of information available anywhere within the BD framework?
Danke Sehr