NAT WAN-LAN Correlation Logs
-
When a host on the LAN connects to a public IP address my Splunk logs show the WAN IP address making the connection. How do I enable/configure logging so that I can see/correlate the original LAN client that made the request?
-
What are you logging?
If you log the allow rule on your lan - then it would show source and dest IP.
-
Works as expected, thanks so much!