Dear Customer,
Based on the IPS logs, device with IP address 140.118.1.91 is initiating RDP connections to multiple destinations at a rate more than 20 times per second.
This device (140.118.1.91) is basically attempted RDP brute force attack.
There could be multiple reasons on hwy the ASOC IPS logs do not match FAZ IPS logs.
Please answer the following :-
1) From where does ASOC receive IPS logs ?
2) What is the Device Serial Number related to ASOC IPS logs