<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to avoid Netflow record for denied traffic in Log Forwarding Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-avoid-netflow-record-for-denied-traffic/m-p/432538#M34</link>
    <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;we have configured Netflow server and the profile is attached to Inside interface, we are getting Netflow records and it seems working fine. but what we have observed is, we are seeing the Netflows for the traffic which is getting denied by Firewall rule also and they are marked as Flow denied in&amp;nbsp; the event type. i am searching for the option to stop sending the netflows for the traffic denied by firewall rule but i could not find any so far. please help me if any one knows how to do it ?&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 08 Sep 2021 08:49:03 GMT</pubDate>
    <dc:creator>Tulasi</dc:creator>
    <dc:date>2021-09-08T08:49:03Z</dc:date>
    <item>
      <title>How to avoid Netflow record for denied traffic</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-avoid-netflow-record-for-denied-traffic/m-p/432538#M34</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;we have configured Netflow server and the profile is attached to Inside interface, we are getting Netflow records and it seems working fine. but what we have observed is, we are seeing the Netflows for the traffic which is getting denied by Firewall rule also and they are marked as Flow denied in&amp;nbsp; the event type. i am searching for the option to stop sending the netflows for the traffic denied by firewall rule but i could not find any so far. please help me if any one knows how to do it ?&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 08:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-avoid-netflow-record-for-denied-traffic/m-p/432538#M34</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2021-09-08T08:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to avoid Netflow record for denied traffic</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-avoid-netflow-record-for-denied-traffic/m-p/435000#M38</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124418"&gt;@Tulasi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The event you are referring to is recorded in the NetFlow Template, Value: 233 (firewallEvent) 3 = Flow denied—The NetFlow data record indicates a flow that firewall policy denied.&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/netflow-monitoring/netflow-templates.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/netflow-monitoring/netflow-templates.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I was searching myself whether there is any way to exclude some flows or build a custom&amp;nbsp;NetFlow Template to exclude some of the values, but I have not found any option to configure it directly on Firewall. Unless you can exclude it on NetFlow Collector/Analyzer side, there is likely no option to do it. I know that with some NetFlow Analyzers it is possible to filter view to exclude some hosts or subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 23:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/how-to-avoid-netflow-record-for-denied-traffic/m-p/435000#M38</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-17T23:21:35Z</dc:date>
    </item>
  </channel>
</rss>

