<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGFW Threat &amp;amp; Traffics Log Fields in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583490#M2968</link>
    <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am going through the traffic and threat logs of the NGFW. In the logs, I am unable to get the knowledge of the following fields " domain" &amp;amp; "config version".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Apr 2024 08:40:45 GMT</pubDate>
    <dc:creator>SwapnilC_Lentra</dc:creator>
    <dc:date>2024-04-12T08:40:45Z</dc:date>
    <item>
      <title>NGFW Threat &amp; Traffics Log Fields</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583490#M2968</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am going through the traffic and threat logs of the NGFW. In the logs, I am unable to get the knowledge of the following fields " domain" &amp;amp; "config version".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 08:40:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583490#M2968</guid>
      <dc:creator>SwapnilC_Lentra</dc:creator>
      <dc:date>2024-04-12T08:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Threat &amp; Traffics Log Fields</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583664#M2973</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/467373333"&gt;@SwapnilC_Lentra&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;would it be possible to post a screen shot of fields you are referring to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 03:14:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583664#M2973</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-04-15T03:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Threat &amp; Traffics Log Fields</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583975#M3000</link>
      <description>&lt;P&gt;Actually I do not have access to the firewall console. I just have raw logs on excel where I got these fields.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 08:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/583975#M3000</guid>
      <dc:creator>SwapnilC_Lentra</dc:creator>
      <dc:date>2024-04-17T08:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: NGFW Threat &amp; Traffics Log Fields</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/584111#M3005</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/467373333"&gt;@SwapnilC_Lentra&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see. Could you please confirm the source of the raw logs? Was it exported directly from Firewall / Panorama or SIEM? Also, if possible could you post samples of what information these fields represent?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 23:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ngfw-threat-amp-traffics-log-fields/m-p/584111#M3005</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-04-17T23:08:09Z</dc:date>
    </item>
  </channel>
</rss>

