Our SIEM dashboard show lot of GKE assets with IOC type IP addresses mapped to it in the dashboard.
I am trying to find out why these are reported on the Global Threat Map with and how these assets are identified as IOC Matches. Customer is also asking for an explanation if these are threats. Can someone give an overview how to correlate this and understand whats going on?

