NAT WAN-LAN Correlation Logs
When a host on the LAN connects to a public IP address my Splunk logs show the WAN IP address making the connection. How do I enable/configure logging so that I can see/correlate the original LAN client that made the request?
What are you logging?
If you log the allow rule on your lan - then it would show source and dest IP.
Works as expected, thanks so much!