<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Improve log filtering workflow with quick “exclude / NOT filter” option from Traffic logs in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/improve-log-filtering-workflow-with-quick-exclude-not-filter/m-p/1256564#M3105</link>
    <description>&lt;P data-end="225" data-start="217"&gt;Hi team,&lt;/P&gt;
&lt;P data-end="225" data-start="217"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="320" data-start="227"&gt;I’d like to suggest a small but impactful improvement to the Traffic Logs filtering workflow.&lt;/P&gt;
&lt;P data-end="577" data-start="322"&gt;Today, when we click on a value in a log entry (e.g. source IP, destination IP, user, etc.), it automatically adds that value to the search bar as a positive filter (e.g. &lt;CODE data-end="497" data-start="493"&gt;eq&lt;/CODE&gt; / &lt;CODE data-end="504" data-start="500"&gt;in&lt;/CODE&gt;). This is extremely useful and significantly speeds up building queries.&lt;/P&gt;
&lt;P data-end="829" data-start="579"&gt;However, during investigations, it is very common to also build exclusion filters (e.g. &lt;CODE data-end="672" data-start="667"&gt;neq&lt;/CODE&gt; / &lt;CODE data-end="683" data-start="675"&gt;not in&lt;/CODE&gt;) while drilling into traffic patterns. Right now, this requires manually editing the query after adding the value, which slows down the workflow.&lt;/P&gt;
&lt;P data-end="944" data-start="831"&gt;&lt;STRONG data-end="846" data-start="831"&gt;Suggestion:&lt;/STRONG&gt;&lt;BR /&gt;Introduce a quick way to add a value as a negated filter directly from the log view. For example:&lt;/P&gt;
&lt;UL data-end="1116" data-start="946"&gt;
&lt;LI data-end="1004" data-start="946" data-section-id="vj70j6"&gt;Standard click → adds positive filter (current behavior)&lt;/LI&gt;
&lt;LI data-end="1116" data-start="1005" data-section-id="9smjmr"&gt;Shift + click (or another modifier / UI option) → adds the same value as a negative filter (&lt;CODE data-end="1104" data-start="1099"&gt;neq&lt;/CODE&gt; / &lt;CODE data-end="1115" data-start="1107"&gt;not in&lt;/CODE&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1370" data-start="1118"&gt;&lt;STRONG data-end="1130" data-start="1118"&gt;Benefit:&lt;/STRONG&gt;&lt;BR /&gt;This would significantly speed up investigative workflows by allowing analysts to quickly include or exclude values without manually editing the query syntax, reducing friction and improving usability during time-sensitive troubleshooting.&lt;/P&gt;
&lt;P data-end="1489" data-start="1372"&gt;Thanks for considering this improvement — it would be a great enhancement for daily SOC / network analysis workflows.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jun 2026 13:09:33 GMT</pubDate>
    <dc:creator>LeonardoMachado</dc:creator>
    <dc:date>2026-06-17T13:09:33Z</dc:date>
    <item>
      <title>Improve log filtering workflow with quick “exclude / NOT filter” option from Traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/improve-log-filtering-workflow-with-quick-exclude-not-filter/m-p/1256564#M3105</link>
      <description>&lt;P data-end="225" data-start="217"&gt;Hi team,&lt;/P&gt;
&lt;P data-end="225" data-start="217"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="320" data-start="227"&gt;I’d like to suggest a small but impactful improvement to the Traffic Logs filtering workflow.&lt;/P&gt;
&lt;P data-end="577" data-start="322"&gt;Today, when we click on a value in a log entry (e.g. source IP, destination IP, user, etc.), it automatically adds that value to the search bar as a positive filter (e.g. &lt;CODE data-end="497" data-start="493"&gt;eq&lt;/CODE&gt; / &lt;CODE data-end="504" data-start="500"&gt;in&lt;/CODE&gt;). This is extremely useful and significantly speeds up building queries.&lt;/P&gt;
&lt;P data-end="829" data-start="579"&gt;However, during investigations, it is very common to also build exclusion filters (e.g. &lt;CODE data-end="672" data-start="667"&gt;neq&lt;/CODE&gt; / &lt;CODE data-end="683" data-start="675"&gt;not in&lt;/CODE&gt;) while drilling into traffic patterns. Right now, this requires manually editing the query after adding the value, which slows down the workflow.&lt;/P&gt;
&lt;P data-end="944" data-start="831"&gt;&lt;STRONG data-end="846" data-start="831"&gt;Suggestion:&lt;/STRONG&gt;&lt;BR /&gt;Introduce a quick way to add a value as a negated filter directly from the log view. For example:&lt;/P&gt;
&lt;UL data-end="1116" data-start="946"&gt;
&lt;LI data-end="1004" data-start="946" data-section-id="vj70j6"&gt;Standard click → adds positive filter (current behavior)&lt;/LI&gt;
&lt;LI data-end="1116" data-start="1005" data-section-id="9smjmr"&gt;Shift + click (or another modifier / UI option) → adds the same value as a negative filter (&lt;CODE data-end="1104" data-start="1099"&gt;neq&lt;/CODE&gt; / &lt;CODE data-end="1115" data-start="1107"&gt;not in&lt;/CODE&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1370" data-start="1118"&gt;&lt;STRONG data-end="1130" data-start="1118"&gt;Benefit:&lt;/STRONG&gt;&lt;BR /&gt;This would significantly speed up investigative workflows by allowing analysts to quickly include or exclude values without manually editing the query syntax, reducing friction and improving usability during time-sensitive troubleshooting.&lt;/P&gt;
&lt;P data-end="1489" data-start="1372"&gt;Thanks for considering this improvement — it would be a great enhancement for daily SOC / network analysis workflows.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 13:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/improve-log-filtering-workflow-with-quick-exclude-not-filter/m-p/1256564#M3105</guid>
      <dc:creator>LeonardoMachado</dc:creator>
      <dc:date>2026-06-17T13:09:33Z</dc:date>
    </item>
  </channel>
</rss>

