Using Open Threat Exchange Reputation data as a policy condition, you can filter events from either the source or destination IP address of an event with more accuracy. To learn more about IP Reputation in USM Appliance, see OTX IP Reputation Data Correlated with Events.
For more detailed instructions, see Configure Reputation as a Condition.