Monitoring Suspicious IP Addresses

View information about activity from suspicious IP addresses that Oracle CASB Cloud Service detects.

Oracle CASB Cloud Service uses data feeds that report on suspicious IP addresses, and matches these with the IP addresses of users who access registered application instances. If Oracle CASB Cloud Service finds a match, it updates the Access Map and the IP address card in the Dashboard, generates a risk event in Risk Events.

  1. Select Dashboard from the Navigation menu. If the Navigation Menu is not displayed, click the Navigation Menu icon Image of the Navigation Menu icon. to display it.
  2. Click the Summary tab.

    The Access Map shows red pins in locations that have experienced activity from suspicious IP addresses.

  3. To view the events from the IP address for a red-pin location, click the pin and then click the "number of events" link in the pop-up that appears over the pin.

    If the first click simply zooms in on the map, click the pin again.

Note:

You can control automatic whitelisting of trusted network addresses by setting a preference. See Setting Your Preferences.

You can also control this preference from the Manage IP Addresses page. See Putting IP Addresses on Blacklists or Whitelists.