# Introduction

**Ver.** 06/03/2026

This plugin retrieves the 500 most frequent IPs from the last 30 days of MISP events and generates a SIEM rule to detect traffic from those IPs.

**Type:** Server Plugin