1- querying DNS and tracing IP in active connections, by double click on the IP, so we can know the domain name of the IP
2- missing in the logs, firewall intrusion attempts used to show the IP of block incoming connection in the logs, no more after CIS 4, can we get it back please
CIS 4 doesn’t show the Source IP of blocked inbound events? It should… or do you mean that you’re not seeing any logged events? This might be because of either a firewall setting and/or rule.