Discover LIVEcommunity — Watch Now

  • 485,781 Members
  • 1,639 Online
  • 170,322 Posts
  • 17,849 Solutions
  • 50,155 Likes

Welcome to Palo Alto Networks LIVEcommunity

Find answers, share solutions, and connect with peers and thought leaders from around the world.
New to LIVEcommunity? Check out our Welcome Guide.

Community Activity

Cotex hostfirewall configuration

Hi Team, This is bit silly question, but i would like to get an expert advice here. I am part of risk assessment team and i was reviewing hostfirewall rules and configuration details and i see the below weird rule set. Is this even really secure configuration..? * We have allowed only approved ports and legitimate application traffic rule. * Rul...

How do you handle Low Severity alerts/issues?

want to know how you guys deal with low severity alerts.. do you monitor/analyze them or only focus on incidents with medium/high/critical severity? do you run any playbook automation against these low sev alerts? are there any best practices from PAN around handling of low severity alerts? i cannot seem to find any. thanks in adv

PA_nts by L4 Transporter
  • 23 Views
  • 0 replies
  • 0 Likes

Trendmicro application identified as "ssl" despite of proper SNI, CN, SAN.

We have the Trend Micro agent installed on the endpoints, and it is running smoothly. However, the application is still being identified as "ssl", even though the packet captures show the correct SNI value in the Client Hello. In the Server Hello, both the SAN and CN fields contain multiple wildcard entries ending with *.trendmicro.com. The URL...

Global Protect and Microsoft Teams e911

Microsoft Teams e911 calling does not display the location when connected to Global Protect. We have split tunneled the Microsoft Teams subnets (i.e. 52.112.0.0/14, 52.122.0.0/15, 52.238.119.141/32, 52.244.160.207/32) as per the Microsoft 365 URLs and IP address ranges (https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-addre...

Password spraying

Hi,Could you provide an XQL query to detect password spraying, specifically when the same IP address attempts logins on multiple AD accounts?Thank you.

Whatsapp (IOS) Traffic not recognized in PaloAlto Firewall

Hi Everyone, We are currently experiencing an issue where WhatsApp on iOS devices is unable to connect, while Android devices and laptops work without any problems. After some investigation and troubleshooting, we found that even after allowing all WhatsApp applications along with their dependencies (including SSL and web-browsing), the issu...

High Availability Latency / Bandwidth Requirements

What are the Latency / Bandwidth Requirements for HA1 interfaces links between 2 HA members? I saw a similar discussion here, but there is no actual answer in it https://live.paloaltonetworks.com/t5/general-topics/high-availability-bandwidth-latency-requirements/m-p/71357 There is another related article: Next-Generation Firewall :HA Timers,...

ET by L2 Linker
  • 273 Views
  • 5 replies
  • 0 Likes

XDR 4 - Integrations AD Query

Hi everyone, on Cortex XDR 4 ,we can build small playbooks, and one of the available actions is AD Query.My question is: what is required to configure this integration? I see that the integration asks for the IP address, domain user, and other parameters, but if the Active Directory is on-premises, how does Cortex XDR establish the connection?Wh...

tlmarques by L4 Transporter
  • 22 Views
  • 0 replies
  • 0 Likes

XDR 4 - default playbooks error

Hi, someone have Cortex XDR 4? i my case, i've adopted some playbooks, and all playbooks have problems with configuration. Configuration using old json values (context values), for example:incident.id and correct is issue.id etc etc

tlmarques by L4 Transporter
  • 22 Views
  • 0 replies
  • 0 Likes

New NGFW Certificaions

So if I understand correctly, the new certifications are technically still the PCNSA/PCNSE. Just broken down into different categories. If this is the case would any existing materials and courses from say CBT Nuggets still be relevant learning materials for the exam?

Thanksgiving & 10 Years of LIVEcommunity: A Quick Thanks and a Big Milestone!

2 min read

A Decade of Showing Up Greetings Everyone! Over the last ten years, this community has become a place people rely on every day. Whether they’re troubleshooting something urgent, sharing hard-earned experience, or helping someone avoid hours of trial and error. What’s kept LIVEcommunity moving forward isn’t marketing or big campaigns. It’s...

10years-celebration-banner.jpg
JayGolf by Community Team Member
  • 342 Views
  • 6 replies
  • 6 Likes

Forward NGFW logs stored in Strata Logging Service to Microsoft Sentinel

I'm trying to forward my NGFW logs that are stored in Strata Logging Service to our SIEM, Microsoft Sentinel. This setup is documented in PAN docs linked here: https://docs.paloaltonetworks.com/prisma-access/integration/microsoft-integrations-with-prisma-access/set-up-https-log-forwarding-to-microsoft-sentinel The issue we are running into ...

HashiCorp Incident Management

3 min read

This blog was written by Sabitha Muppuri (Sr Staff Site Reliability Engineer) The Critical Need for Vendor Tool Health Monitoring in Orchestration Environments In today's highly orchestrated and autoscaling cloud environments, vendor tool health plays an important role in maintaining application stability and performance. This blog entry wil...

JayGolf_2-1764186798077.png
JayGolf_3-1764186843652.png
JayGolf_6-1764194324927.png
JayGolf_7-1764194361331.png
JayGolf by Community Team Member
  • 121 Views
  • 0 replies
  • 0 Likes

Upcoming Fuel Events

Top Solution Authors
Top Contributors

Latest from our Blog

HashiCorp Incident Management

This blog was written by Sabitha Muppuri (Sr Staff Site Reliability Engineer) The Critical Need for Vendor Tool Health Monitoring in Orchestration Environments In today's highly orchestrated and autos...

0 Comments