<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unusual server port activity Internal Alerts Potential False Positives in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unusual-server-port-activity-internal-alerts-potential-false/m-p/364889#M336</link>
    <description>&lt;P&gt;I have the thresholds for Unusual Server Port Internal activity set to the most conservative settings to minimize false positives but it seems like the highest port consistently gets flagged as "unusual".&amp;nbsp; In the example below there are 15 ports labeled as usual and the Kafka port (9092) is being flagged as unusual.&amp;nbsp; Upon further investigation we always find out that this is the intended purpose and traffic volumes support that this is normal activity.&amp;nbsp; For example another similar alert was fired off on MongoDB but going into the investigate tab I can see months and hundreds of Gb of Mongo DB traffic so it should NOT have flagged this traffic coming from a host labeled as MongoDB (not that the naming convention has anything to do with it but I had to figure out if the resource this was connected to was legit a MongoDB server and client).&lt;BR /&gt;&lt;BR /&gt;I may enter a feature request to give "allowed ports" check box based on alerts generated for Unusual server port Internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UnusualHighPortActivity.png" style="width: 794px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28771iA6A337416AEE3542/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UnusualHighPortActivity.png" alt="UnusualHighPortActivity.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Nov 2020 17:24:34 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2020-11-23T17:24:34Z</dc:date>
    <item>
      <title>Unusual server port activity Internal Alerts Potential False Positives</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unusual-server-port-activity-internal-alerts-potential-false/m-p/364889#M336</link>
      <description>&lt;P&gt;I have the thresholds for Unusual Server Port Internal activity set to the most conservative settings to minimize false positives but it seems like the highest port consistently gets flagged as "unusual".&amp;nbsp; In the example below there are 15 ports labeled as usual and the Kafka port (9092) is being flagged as unusual.&amp;nbsp; Upon further investigation we always find out that this is the intended purpose and traffic volumes support that this is normal activity.&amp;nbsp; For example another similar alert was fired off on MongoDB but going into the investigate tab I can see months and hundreds of Gb of Mongo DB traffic so it should NOT have flagged this traffic coming from a host labeled as MongoDB (not that the naming convention has anything to do with it but I had to figure out if the resource this was connected to was legit a MongoDB server and client).&lt;BR /&gt;&lt;BR /&gt;I may enter a feature request to give "allowed ports" check box based on alerts generated for Unusual server port Internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UnusualHighPortActivity.png" style="width: 794px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28771iA6A337416AEE3542/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UnusualHighPortActivity.png" alt="UnusualHighPortActivity.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 17:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unusual-server-port-activity-internal-alerts-potential-false/m-p/364889#M336</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-11-23T17:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unusual server port activity Internal Alerts Potential False Positives</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unusual-server-port-activity-internal-alerts-potential-false/m-p/511714#M606</link>
      <description>&lt;P&gt;Greetings Ramyfrahman,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that this note finds you well! I know that it has been a while since you had posted this question but I wanted to see if you still potentially needed any help. Thank you for your time and I hope that you have a good remainder of your day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;J. Avery King&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 14:38:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/unusual-server-port-activity-internal-alerts-potential-false/m-p/511714#M606</guid>
      <dc:creator>AKing9</dc:creator>
      <dc:date>2022-08-12T14:38:00Z</dc:date>
    </item>
  </channel>
</rss>

