<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block OpenAI within iTerm2, but allow through browser in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588501#M779</link>
    <description>&lt;P&gt;And to be fair the URL is shared with the Python integration we want to allow, so it needs to be by the UserAgent of iterm2&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2024 13:31:33 GMT</pubDate>
    <dc:creator>TravisFleming</dc:creator>
    <dc:date>2024-05-31T13:31:33Z</dc:date>
    <item>
      <title>Block OpenAI within iTerm2, but allow through browser</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588146#M773</link>
      <description>&lt;P&gt;Hello, I know it's silly, but we are looking to do just what the subject of this topic says. With the release of iTerm2 version 3.5.0 there are ai integrations to OpenAI. We want to block this traffic if it's from the "&lt;SPAN class="key-name"&gt;UserAgent&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;iTerm2/3.5.0", but allow this traffic if it's web based. I know that sounds silly, but that's the request in my company.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;I was trying to create a custom vulnerability with the UserAgent, but I'm not seeing that as an option. What else are we doing in order to block this via Palo?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;We are able to get more details with a log ingestion too, but below is the criteria of traffic we are looking to block from a single log avent. If all of these are true, block, else allow it:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;&lt;SPAN class="key-name"&gt;Application&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;openai-api&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;&lt;SPAN class="key-name"&gt;URL&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string h" data-path="URL"&gt;api.openai.com/v1/chat/completions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;&lt;SPAN class="t string h" data-path="URL"&gt;&lt;SPAN class="key-name"&gt;URLCategory&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;artificial-intelligence&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;&lt;SPAN class="t string h" data-path="URL"&gt;&lt;SPAN class="key-name"&gt;UserAgent&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;iTerm2/3.5.0 CFNetwork/1496.0.7 Darwin/23.5.0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 28 May 2024 20:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588146#M773</guid>
      <dc:creator>TravisFleming</dc:creator>
      <dc:date>2024-05-28T20:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Block OpenAI within iTerm2, but allow through browser</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588465#M777</link>
      <description>&lt;P&gt;First, In order for this to work, you need to make sure that traffic is decrypted. The web TLS traffic might be easy to do, but the iterm who knows. When traffic is not decrypted you are at the merci of using the SAN value in the certificate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, I am assuming that the iterm trafifc is through the API, if the traffic is not getting decrypt, might not match the web traffic because the certificate might be different. What I would do is setup a policy to allow the decrypted traffic using the App-ID and URL filtering and then block the API traffic based on their IPs based on this information&lt;BR /&gt;&lt;A href="https://platform.openai.com/docs/actions/production" target="_blank" rel="noopener"&gt;https://platform.openai.com/docs/actions/production&lt;/A&gt;&lt;BR /&gt;See if that works, or perhaps you might need to block the API first, check the traffic patterns to see what works best.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 08:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588465#M777</guid>
      <dc:creator>SuperMario</dc:creator>
      <dc:date>2024-05-31T08:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Block OpenAI within iTerm2, but allow through browser</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588500#M778</link>
      <description>&lt;P&gt;Hello. Yes we are decrypting the traffic no issues there. We do want to allow other openai-api calls through the browser, specifically want to block with the use of the iTerm2 application. Now I can setup a policy to block traffic to that URL, with the App-ID of Openai-api, and that will get me closer. However if the URL changes I don't want to have to keep updating the rule. I'm more curious how to create a custom vulnerability based on the UserAgent field I see from our 3rd party logging tool the Palo logs don't show me in Panorama?&lt;/P&gt;
&lt;P&gt;Here is more of the 3rd party log with any company information redacted. I bolded some fields of interest I would like to use for the custom vulnerability. However I'm not finding any Palo documentation to explain their different "context" fields when creating the signature of a custom vulnerability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Action&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="Action"&gt;allow&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Application&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string" data-path="Application"&gt;openai-api&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ConfigVersion&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="ConfigVersion"&gt;10.2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ContainerID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="ContainerID"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ContainerName&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="ContainerName"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ContainerNameSpace&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="ContainerNameSpace"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ContentType&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="ContentType"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ContentVersion&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="ContentVersion"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DGHierarchyLevel1&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="DGHierarchyLevel1"&gt;21&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DGHierarchyLevel2&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="DGHierarchyLevel2"&gt;18&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DGHierarchyLevel3&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="DGHierarchyLevel3"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DGHierarchyLevel4&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="DGHierarchyLevel4"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationAddress&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="DestinationAddress"&gt;104.18.6.192&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceCategory&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceCategory"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceHost&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceHost"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceMac&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceMac"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceModel&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceModel"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceOSFamily&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceOSFamily"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceOSVersion&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceOSVersion"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceProfile&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceProfile"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDeviceVendor&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDeviceVendor"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationDynamicAddressGroup&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationDynamicAddressGroup"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationEDL&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationEDL"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationLocation&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="DestinationLocation"&gt;US&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationPort&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="DestinationPort"&gt;443&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationUUID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationUUID"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DestinationUser&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DestinationUser"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DeviceName&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="DeviceName"&gt;GP cloud service&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DeviceSN&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="DeviceSN"&gt;no-serial&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DirectionOfAttack&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="DirectionOfAttack"&gt;client to server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;DynamicUserGroupName&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="DynamicUserGroupName"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;EndpointSerialNumber&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="EndpointSerialNumber"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;FromZone&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="FromZone"&gt;trust&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;HTTP2Connection&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="HTTP2Connection"&gt;247541&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;HTTPHeaders&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="HTTPHeaders"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;HTTPMethod&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="HTTPMethod"&gt;post&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;HostID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="HostID"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;IMEI&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="IMEI"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;IMSI&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="IMSI"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;InboundInterface&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="InboundInterface"&gt;tunnel.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;InlineMLVerdict&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="InlineMLVerdict"&gt;unknown&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;LogSetting&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="LogSetting"&gt;Redacted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;LogType&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="LogType"&gt;THREAT&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;NATDestination&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="NATDestination"&gt;104.18.6.192&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;NATDestinationPort&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="NATDestinationPort"&gt;443&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;NATSource&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="NATSource"&gt;Redacted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;NATSourcePort&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="NATSourcePort"&gt;56324&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;NSSAINetworkSliceType&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="NSSAINetworkSliceType"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;OutboundInterface&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="OutboundInterface"&gt;ethernet1/1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;PacketID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="PacketID"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ParentSessionID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="ParentSessionID"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ParentStarttime&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="ParentStarttime"&gt;2024-05-31T13:01:27.000000Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Protocol&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="Protocol"&gt;tcp&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Referer&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="Referer"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;RepeatCount&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="RepeatCount"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Rule&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="Rule"&gt;Redacted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;RuleUUID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="RuleUUID"&gt;b12c9089-9de8-482c-bf07-d9ca3f0197c0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SequenceNo&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t bigint" data-path="SequenceNo"&gt;7364170906109984247&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SessionID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="SessionID"&gt;848202&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SigFlags&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="SigFlags"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceAddress&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="SourceAddress"&gt;Redacted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceCategory&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceCategory"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceHost&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceHost"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceMac&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceMac"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceModel&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceModel"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceOSFamily&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceOSFamily"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceOSVersion&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceOSVersion"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceProfile&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceProfile"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDeviceVendor&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDeviceVendor"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceDynamicAddressGroup&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceDynamicAddressGroup"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceEDL&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceEDL"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceLocation&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="SourceLocation"&gt;Redacted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourcePort&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="SourcePort"&gt;50070&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceUUID&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="SourceUUID"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;SourceUser&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="SourceUser"&gt;Redacted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Subtype&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="Subtype"&gt;url&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;TimeGenerated&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="TimeGenerated"&gt;2024-05-31T13:01:28.000000Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;TimeGeneratedHighResolution&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="TimeGeneratedHighResolution"&gt;2024-05-31T13:01:29.508000Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;TimeReceived&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="TimeReceived"&gt;2024-05-31T13:01:33.000000Z&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;ToZone&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="ToZone"&gt;untrust&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Tunnel&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="Tunnel"&gt;N/A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;URL&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string" data-path="URL"&gt;api.openai.com/v1/chat/completions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;URLCategory&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="URLCategory"&gt;artificial-intelligence&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;URLCategoryList&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="URLCategoryList"&gt;artificial-intelligence,computer-and-internet-info,low-risk&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;URLCounter&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t number" data-path="URLCounter"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;STRONG&gt;&lt;SPAN class="key-name"&gt;UserAgent&lt;/SPAN&gt;:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN class="t string" data-path="UserAgent"&gt;&lt;STRONG&gt;iTerm2/3.5.0&lt;/STRONG&gt; CFNetwork/1496.0.7 Darwin/23.5.0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;VendorSeverity&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="VendorSeverity"&gt;Informational&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;VirtualLocation&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t string" data-path="VirtualLocation"&gt;vsys1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;VirtualSystemName&lt;/SPAN&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;X-Forwarded-For&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="X-Forwarded-For"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;X-Forwarded-ForIP&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t null" data-path="X-Forwarded-ForIP"&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 13:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588500#M778</guid>
      <dc:creator>TravisFleming</dc:creator>
      <dc:date>2024-05-31T13:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Block OpenAI within iTerm2, but allow through browser</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588501#M779</link>
      <description>&lt;P&gt;And to be fair the URL is shared with the Python integration we want to allow, so it needs to be by the UserAgent of iterm2&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 13:31:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/block-openai-within-iterm2-but-allow-through-browser/m-p/588501#M779</guid>
      <dc:creator>TravisFleming</dc:creator>
      <dc:date>2024-05-31T13:31:33Z</dc:date>
    </item>
  </channel>
</rss>

