<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat ID #9999' generated by PAN NGFW in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/472281#M1659</link>
    <description>&lt;P&gt;The thing is that these URL are benign. See screenshot. It creates an alert for a benign link under threat ID 9999, but according to the documentation -&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;9999— URL filtering log&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;I cannot understand, why I have a alert for a benign link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On NGFW all URL categories are set for an alert, but in case that URL, etc,.. is benign, there is no need to create an alert in XDR, right?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 10:29:38 GMT</pubDate>
    <dc:creator>LukasB</dc:creator>
    <dc:date>2022-03-11T10:29:38Z</dc:date>
    <item>
      <title>Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/470909#M1622</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have turned off alerts on NGFW for &lt;EM&gt;Private URL,&amp;nbsp;&lt;/EM&gt;but I still get threat ID #9999.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can somebody a little bit more explain what this threat ID means? I am trying to clean it up, but still get these alerts.&lt;/P&gt;&lt;P&gt;And it is not any kind of malicious traffic.&lt;/P&gt;&lt;P&gt;It is usually connected with some internal web-pages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can provide more info, if needed.&lt;/P&gt;&lt;P&gt;Lukas&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 13:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/470909#M1622</guid>
      <dc:creator>LukasB</dc:creator>
      <dc:date>2022-03-07T13:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/471253#M1626</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132156"&gt;@LukasB&lt;/a&gt;, the source of the alerts are from NGFW, as you've correctly stated. Threat ID 9999 refers to URL filtering (see &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields.html" target="_blank"&gt;here&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a KB that explains the various categories for URL filtering:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5hCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5hCAC&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can look into the alert details to determine the URL, and take action from there (block etc.), which gets driven by your firewall configurations.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 09:24:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/471253#M1626</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-08T09:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/472281#M1659</link>
      <description>&lt;P&gt;The thing is that these URL are benign. See screenshot. It creates an alert for a benign link under threat ID 9999, but according to the documentation -&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;9999— URL filtering log&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;I cannot understand, why I have a alert for a benign link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On NGFW all URL categories are set for an alert, but in case that URL, etc,.. is benign, there is no need to create an alert in XDR, right?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 10:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/472281#M1659</guid>
      <dc:creator>LukasB</dc:creator>
      <dc:date>2022-03-11T10:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/472282#M1660</link>
      <description>&lt;P&gt;another example - alert for an URL of drug store, but benign. can be seen that the URL is opened from Outlook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 10:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/472282#M1660</guid>
      <dc:creator>LukasB</dc:creator>
      <dc:date>2022-03-11T10:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/474586#M1727</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132156"&gt;@LukasB&lt;/a&gt;&amp;nbsp;sorry I missed your earlier comments. Please&amp;nbsp;@ whoever commented so that we get a notification as well. I hope you understand.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;URL's do occasionally get recategorized for several reasons. If the URL is benign and you are confident of its category, you'll have to raise a URL recategorization request through the standard channels. Please refer to this link here: &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/url-filtering/url-category-change.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/url-filtering/url-category-change.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&amp;nbsp; Also, please note that this is a Cortex XDR forum, you should consider posting in the &lt;A href="https://live.paloaltonetworks.com/t5/panorama-discussions/bd-p/Panorama_Discussions" target="_blank"&gt;Panorama forums&lt;/A&gt; for better traction.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/474586#M1727</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-03-21T10:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/544197#M4464</link>
      <description>&lt;P&gt;I know this is the Cortex XDR forum, but did you ever find a solution for this on your PANOS device? We are seeing the same behavior after some recent upgrades and enabling cloud inline categorization. Palo support referred me to this thread, but the issue is not that the URL category is wrong or blocked - the issue is that PANOS is issuing a&amp;nbsp;flood of “high” severity events with inline categorization verdict of “cloud”, category of “any”, and action as “alert” on what appear to be entirely benign sites whose URL filtering category is explicitly allowed.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 15:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/544197#M4464</guid>
      <dc:creator>phite_cpso</dc:creator>
      <dc:date>2023-05-31T15:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID #9999' generated by PAN NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/1236752#M8693</link>
      <description>&lt;P&gt;This is an old thread, but I found it to be Credential Phishing Prevention.&amp;nbsp; Check the Flags under the Detailed Logs.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 02:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/threat-id-9999-generated-by-pan-ngfw/m-p/1236752#M8693</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-08-27T02:15:55Z</dc:date>
    </item>
  </channel>
</rss>

