Introduction Ver. 06/03/2026 This plugin retrieves the 500 most frequent IPs from the last 30 days of MISP events and generates a SIEM rule to detect traffic from those IPs. Type: Server Plugin