<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security to detect specific device in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-to-detect-specific-device/m-p/1263532#M2520</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="450" data-start="264"&gt;For what you’re describing, I’d do it in &lt;STRONG data-end="375" data-start="305"&gt;Palo Alto Device Security / IoT Security using a Custom Alert Rule&lt;/STRONG&gt;, with the &lt;STRONG data-end="400" data-start="386"&gt;OUI Vendor&lt;/STRONG&gt; or a tag/custom attribute identifying those OUIs.&lt;/P&gt;
&lt;P data-end="686" data-start="452"&gt;Palo Alto’s current Device Security platform explicitly tracks &lt;STRONG data-end="542" data-start="515"&gt;OUI Vendor (NIC vendor)&lt;/STRONG&gt; separately from the device’s normal &lt;STRONG data-end="589" data-start="579"&gt;Vendor&lt;/STRONG&gt; attribute. The OUI Vendor is derived from the MAC address.&lt;/P&gt;
&lt;H3 data-end="712" data-start="688" data-section-id="erdilh"&gt;Recommended approach&lt;/H3&gt;
&lt;P data-end="755" data-start="714"&gt;In Device Security / IoT Security, go to:&lt;/P&gt;
&lt;P data-end="802" data-start="757"&gt;&lt;STRONG data-end="802" data-start="757"&gt;Alerts → Custom Alert Rules → Create Rule&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="826" data-start="804"&gt;Create something like:&lt;/P&gt;
&lt;BLOCKQUOTE data-end="1060" data-start="828"&gt;
&lt;P data-end="1060" data-start="830"&gt;&lt;STRONG data-end="839" data-start="830"&gt;Rule:&lt;/STRONG&gt; Unauthorized Vendor Device Connected&lt;BR data-end="879" data-start="876" /&gt;&lt;STRONG data-end="895" data-start="881"&gt;Condition:&lt;/STRONG&gt; Change Event → &lt;STRONG data-end="935" data-start="911"&gt;New Device Discovery&lt;/STRONG&gt;&lt;BR data-end="938" data-start="935" /&gt;&lt;STRONG data-end="958" data-start="940"&gt;Target Device:&lt;/STRONG&gt; devices matching your vendor/OUI criteria&lt;BR data-end="1003" data-start="1000" /&gt;&lt;STRONG data-end="1016" data-start="1005"&gt;Action:&lt;/STRONG&gt; Generate Alert / Email / send to SIEM, etc.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P data-end="1348" data-start="1062"&gt;Palo Alto specifically supports &lt;STRONG data-end="1118" data-start="1094"&gt;New Device Discovery&lt;/STRONG&gt; as a Change Event, which makes it a good fit for “tell me whenever one of these devices first appears.” Custom alert rules can also notify users or forward the alert into third-party systems.&lt;/P&gt;
&lt;P data-end="1687" data-start="1350"&gt;The one wrinkle is that the Custom Alert Rule editor does not appear to expose raw &lt;STRONG data-end="1451" data-start="1433"&gt;MAC prefix/OUI&lt;/STRONG&gt; as one of its documented direct target selectors. Palo Alto documents target selectors such as IP, subnet, VLAN, tags, custom attributes, category/profile, switch/AP, and related device attributes.&lt;/P&gt;
&lt;P data-end="1717" data-start="1689"&gt;So I would use this pattern:&lt;/P&gt;
&lt;P data-end="1771" data-start="1719"&gt;&lt;STRONG data-end="1771" data-start="1719"&gt;1. Identify the devices by OUI Vendor / MAC OUI.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="2044" data-start="1773"&gt;In &lt;STRONG data-end="1796" data-start="1776"&gt;Assets → Devices&lt;/STRONG&gt;, use the Query Builder/filtering to find devices matching the OUI/vendor you care about. Device Security has an &lt;STRONG data-end="1923" data-start="1909"&gt;OUI Vendor&lt;/STRONG&gt; field specifically representing the NIC manufacturer derived from the MAC address.&lt;/P&gt;
&lt;P data-end="2082" data-start="2046"&gt;For example, suppose you care about:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;AA:BB:CC
11:22:33
DE:AD:BE&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2122" data-start="2084"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2177" data-start="2124"&gt;and Device Security resolves those to something like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Acme Wireless
Example IoT Corp
Contoso Electronics&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2241" data-start="2179"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2367" data-start="2243"&gt;Ideally filter on &lt;STRONG data-end="2275" data-start="2261"&gt;OUI Vendor&lt;/STRONG&gt; rather than the device-level &lt;CODE data-end="2313" data-start="2305"&gt;Vendor&lt;/CODE&gt;, because those mean different things in IoT Security.&lt;/P&gt;
&lt;P data-end="2437" data-start="2369"&gt;&lt;STRONG data-end="2437" data-start="2369"&gt;2. Create a tag/custom attribute for the devices you care about.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="2451" data-start="2439"&gt;For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Custom Attribute:
Monitored_OUI = Yes&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2502" data-start="2453"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2513" data-start="2504"&gt;or a tag:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Restricted-OUI&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2541" data-start="2515"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2730" data-start="2543"&gt;Device Security supports automatically assigning custom attributes based on saved device filters. You create the device filter first, then create an IF/THEN custom attribute rule such as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;IF device matches &amp;lt;Restricted-OUI-vendors&amp;gt;
THEN Monitored_OUI = Yes&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2811" data-start="2732"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2945" data-start="2813"&gt;New devices matching that filter will subsequently receive the custom attribute automatically.&lt;/P&gt;
&lt;P data-end="2987" data-start="2947"&gt;Then your alert rule becomes very clean:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;WHEN
    Custom Attribute "Monitored_OUI" = "Yes"
AND
    Change Event = New Device Discovery

DO
    Generate High Severity Alert
    Notify Security Team&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="3156" data-start="2989"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="3192" data-start="3158"&gt;That’s the architecture I’d favor.&lt;/P&gt;
&lt;H3 data-end="3254" data-start="3194" data-section-id="1lu3wac"&gt;There may be an even better option in the newer platform&lt;/H3&gt;
&lt;P data-end="3573" data-start="3256"&gt;If you're on the newer &lt;STRONG data-end="3322" data-start="3279"&gt;Device Security in Strata Cloud Manager&lt;/STRONG&gt;, Palo Alto introduced &lt;STRONG data-end="3375" data-start="3345"&gt;Action Center in June 2026&lt;/STRONG&gt;. It can scope devices using device criteria, trigger on &lt;STRONG data-end="3446" data-start="3432"&gt;New Device&lt;/STRONG&gt;, and then automatically &lt;STRONG data-end="3534" data-start="3471"&gt;add a tag, raise a security alert, or perform other actions&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="3643" data-start="3575"&gt;So on a current tenant, you may be able to simplify this to roughly:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Scope:
    OUI Vendor IN (
       Vendor-A,
       Vendor-B,
       Vendor-C
    )

Trigger:
    New Device

Actions:
    Add tag "Restricted-OUI"
    Raise Security Alert&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="3828" data-start="3645"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="3884" data-start="3830"&gt;That would be preferable to shoehorning this into HIP.&lt;/P&gt;
&lt;H3 data-end="3915" data-start="3886" data-section-id="1dpgf4m"&gt;One important distinction&lt;/H3&gt;
&lt;P data-end="3960" data-start="3917"&gt;Be careful about &lt;STRONG data-end="3959" data-start="3934"&gt;Vendor vs. OUI Vendor&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="4007" data-start="3962"&gt;Palo Alto treats them as separate attributes:&lt;/P&gt;
&lt;DIV class="group TyagGW_tableContainer"&gt;
&lt;DIV class="TyagGW_tableWrapper flex flex-col-reverse w-fit" tabindex="-1"&gt;
&lt;TABLE class="w-fit min-w-(--thread-content-width)" data-end="4183" data-start="4009"&gt;
&lt;THEAD data-end="4032" data-start="4009"&gt;
&lt;TR data-end="4032" data-start="4009"&gt;
&lt;TH class="last:pe-10" data-col-size="sm" data-end="4021" data-start="4009"&gt;Attribute&lt;/TH&gt;
&lt;TH class="last:pe-10" data-col-size="md" data-end="4032" data-start="4021"&gt;Meaning&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY data-end="4183" data-start="4043"&gt;
&lt;TR data-end="4114" data-start="4043"&gt;
&lt;TD data-col-size="sm" data-end="4056" data-start="4043"&gt;&lt;STRONG data-end="4055" data-start="4045"&gt;Vendor&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD data-col-size="md" data-end="4114" data-start="4056"&gt;Manufacturer Palo Alto believes made the actual device&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-end="4183" data-start="4115"&gt;
&lt;TD data-col-size="sm" data-end="4132" data-start="4115"&gt;&lt;STRONG data-end="4131" data-start="4117"&gt;OUI Vendor&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD data-col-size="md" data-end="4183" data-start="4132"&gt;Manufacturer associated with the NIC/MAC prefix&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="4234" data-start="4185"&gt;For example, an industrial controller could have:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Vendor: Siemens
OUI Vendor: Intel&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="4281" data-start="4236"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="4324" data-start="4283"&gt;because Intel made the network interface.&lt;/P&gt;
&lt;P data-end="4510" data-start="4326"&gt;If your requirement is specifically &lt;STRONG data-end="4445" data-start="4362"&gt;“alert me when these MAC OUIs appear,” use OUI Vendor / MAC-derived information&lt;/STRONG&gt;, not simply Device Vendor.&lt;/P&gt;
&lt;P data-end="4715" data-start="4512"&gt;And one other consideration: randomized/private MAC addresses can make OUI-based detection unreliable for some Wi-Fi clients, although that's generally less of an issue with fixed-purpose IoT/OT devices.&lt;/P&gt;
&lt;P data-end="4753" data-start="4717"&gt;So conceptually, I'd build yours as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;MAC/OUI
   ↓
Device Security identifies OUI Vendor
   ↓
Saved filter / custom attribute or tag
   ↓
New Device Discovery
   ↓
Custom Alert
   ↓
Email / SIEM / SOC notification&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="4942" data-start="4755"&gt;&amp;nbsp;&lt;/PRE&gt;</description>
    <pubDate>Wed, 02 Sep 2026 18:05:55 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2026-09-02T18:05:55Z</dc:date>
    <item>
      <title>Security to detect specific device</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-to-detect-specific-device/m-p/1263343#M2519</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;How do I set up a custom alert in IoT Security to detect specific device vendors? I have several MAC vendor/OUI codes and want an alert whenever a device matching one of them connects to our network.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2026 06:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-to-detect-specific-device/m-p/1263343#M2519</guid>
      <dc:creator>ali066khan</dc:creator>
      <dc:date>2026-09-01T06:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security to detect specific device</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-to-detect-specific-device/m-p/1263532#M2520</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="450" data-start="264"&gt;For what you’re describing, I’d do it in &lt;STRONG data-end="375" data-start="305"&gt;Palo Alto Device Security / IoT Security using a Custom Alert Rule&lt;/STRONG&gt;, with the &lt;STRONG data-end="400" data-start="386"&gt;OUI Vendor&lt;/STRONG&gt; or a tag/custom attribute identifying those OUIs.&lt;/P&gt;
&lt;P data-end="686" data-start="452"&gt;Palo Alto’s current Device Security platform explicitly tracks &lt;STRONG data-end="542" data-start="515"&gt;OUI Vendor (NIC vendor)&lt;/STRONG&gt; separately from the device’s normal &lt;STRONG data-end="589" data-start="579"&gt;Vendor&lt;/STRONG&gt; attribute. The OUI Vendor is derived from the MAC address.&lt;/P&gt;
&lt;H3 data-end="712" data-start="688" data-section-id="erdilh"&gt;Recommended approach&lt;/H3&gt;
&lt;P data-end="755" data-start="714"&gt;In Device Security / IoT Security, go to:&lt;/P&gt;
&lt;P data-end="802" data-start="757"&gt;&lt;STRONG data-end="802" data-start="757"&gt;Alerts → Custom Alert Rules → Create Rule&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="826" data-start="804"&gt;Create something like:&lt;/P&gt;
&lt;BLOCKQUOTE data-end="1060" data-start="828"&gt;
&lt;P data-end="1060" data-start="830"&gt;&lt;STRONG data-end="839" data-start="830"&gt;Rule:&lt;/STRONG&gt; Unauthorized Vendor Device Connected&lt;BR data-end="879" data-start="876" /&gt;&lt;STRONG data-end="895" data-start="881"&gt;Condition:&lt;/STRONG&gt; Change Event → &lt;STRONG data-end="935" data-start="911"&gt;New Device Discovery&lt;/STRONG&gt;&lt;BR data-end="938" data-start="935" /&gt;&lt;STRONG data-end="958" data-start="940"&gt;Target Device:&lt;/STRONG&gt; devices matching your vendor/OUI criteria&lt;BR data-end="1003" data-start="1000" /&gt;&lt;STRONG data-end="1016" data-start="1005"&gt;Action:&lt;/STRONG&gt; Generate Alert / Email / send to SIEM, etc.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P data-end="1348" data-start="1062"&gt;Palo Alto specifically supports &lt;STRONG data-end="1118" data-start="1094"&gt;New Device Discovery&lt;/STRONG&gt; as a Change Event, which makes it a good fit for “tell me whenever one of these devices first appears.” Custom alert rules can also notify users or forward the alert into third-party systems.&lt;/P&gt;
&lt;P data-end="1687" data-start="1350"&gt;The one wrinkle is that the Custom Alert Rule editor does not appear to expose raw &lt;STRONG data-end="1451" data-start="1433"&gt;MAC prefix/OUI&lt;/STRONG&gt; as one of its documented direct target selectors. Palo Alto documents target selectors such as IP, subnet, VLAN, tags, custom attributes, category/profile, switch/AP, and related device attributes.&lt;/P&gt;
&lt;P data-end="1717" data-start="1689"&gt;So I would use this pattern:&lt;/P&gt;
&lt;P data-end="1771" data-start="1719"&gt;&lt;STRONG data-end="1771" data-start="1719"&gt;1. Identify the devices by OUI Vendor / MAC OUI.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="2044" data-start="1773"&gt;In &lt;STRONG data-end="1796" data-start="1776"&gt;Assets → Devices&lt;/STRONG&gt;, use the Query Builder/filtering to find devices matching the OUI/vendor you care about. Device Security has an &lt;STRONG data-end="1923" data-start="1909"&gt;OUI Vendor&lt;/STRONG&gt; field specifically representing the NIC manufacturer derived from the MAC address.&lt;/P&gt;
&lt;P data-end="2082" data-start="2046"&gt;For example, suppose you care about:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;AA:BB:CC
11:22:33
DE:AD:BE&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2122" data-start="2084"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2177" data-start="2124"&gt;and Device Security resolves those to something like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Acme Wireless
Example IoT Corp
Contoso Electronics&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2241" data-start="2179"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2367" data-start="2243"&gt;Ideally filter on &lt;STRONG data-end="2275" data-start="2261"&gt;OUI Vendor&lt;/STRONG&gt; rather than the device-level &lt;CODE data-end="2313" data-start="2305"&gt;Vendor&lt;/CODE&gt;, because those mean different things in IoT Security.&lt;/P&gt;
&lt;P data-end="2437" data-start="2369"&gt;&lt;STRONG data-end="2437" data-start="2369"&gt;2. Create a tag/custom attribute for the devices you care about.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="2451" data-start="2439"&gt;For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Custom Attribute:
Monitored_OUI = Yes&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2502" data-start="2453"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2513" data-start="2504"&gt;or a tag:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Restricted-OUI&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2541" data-start="2515"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2730" data-start="2543"&gt;Device Security supports automatically assigning custom attributes based on saved device filters. You create the device filter first, then create an IF/THEN custom attribute rule such as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;IF device matches &amp;lt;Restricted-OUI-vendors&amp;gt;
THEN Monitored_OUI = Yes&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="2811" data-start="2732"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="2945" data-start="2813"&gt;New devices matching that filter will subsequently receive the custom attribute automatically.&lt;/P&gt;
&lt;P data-end="2987" data-start="2947"&gt;Then your alert rule becomes very clean:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;WHEN
    Custom Attribute "Monitored_OUI" = "Yes"
AND
    Change Event = New Device Discovery

DO
    Generate High Severity Alert
    Notify Security Team&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="3156" data-start="2989"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="3192" data-start="3158"&gt;That’s the architecture I’d favor.&lt;/P&gt;
&lt;H3 data-end="3254" data-start="3194" data-section-id="1lu3wac"&gt;There may be an even better option in the newer platform&lt;/H3&gt;
&lt;P data-end="3573" data-start="3256"&gt;If you're on the newer &lt;STRONG data-end="3322" data-start="3279"&gt;Device Security in Strata Cloud Manager&lt;/STRONG&gt;, Palo Alto introduced &lt;STRONG data-end="3375" data-start="3345"&gt;Action Center in June 2026&lt;/STRONG&gt;. It can scope devices using device criteria, trigger on &lt;STRONG data-end="3446" data-start="3432"&gt;New Device&lt;/STRONG&gt;, and then automatically &lt;STRONG data-end="3534" data-start="3471"&gt;add a tag, raise a security alert, or perform other actions&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="3643" data-start="3575"&gt;So on a current tenant, you may be able to simplify this to roughly:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Scope:
    OUI Vendor IN (
       Vendor-A,
       Vendor-B,
       Vendor-C
    )

Trigger:
    New Device

Actions:
    Add tag "Restricted-OUI"
    Raise Security Alert&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="3828" data-start="3645"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="3884" data-start="3830"&gt;That would be preferable to shoehorning this into HIP.&lt;/P&gt;
&lt;H3 data-end="3915" data-start="3886" data-section-id="1dpgf4m"&gt;One important distinction&lt;/H3&gt;
&lt;P data-end="3960" data-start="3917"&gt;Be careful about &lt;STRONG data-end="3959" data-start="3934"&gt;Vendor vs. OUI Vendor&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="4007" data-start="3962"&gt;Palo Alto treats them as separate attributes:&lt;/P&gt;
&lt;DIV class="group TyagGW_tableContainer"&gt;
&lt;DIV class="TyagGW_tableWrapper flex flex-col-reverse w-fit" tabindex="-1"&gt;
&lt;TABLE class="w-fit min-w-(--thread-content-width)" data-end="4183" data-start="4009"&gt;
&lt;THEAD data-end="4032" data-start="4009"&gt;
&lt;TR data-end="4032" data-start="4009"&gt;
&lt;TH class="last:pe-10" data-col-size="sm" data-end="4021" data-start="4009"&gt;Attribute&lt;/TH&gt;
&lt;TH class="last:pe-10" data-col-size="md" data-end="4032" data-start="4021"&gt;Meaning&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY data-end="4183" data-start="4043"&gt;
&lt;TR data-end="4114" data-start="4043"&gt;
&lt;TD data-col-size="sm" data-end="4056" data-start="4043"&gt;&lt;STRONG data-end="4055" data-start="4045"&gt;Vendor&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD data-col-size="md" data-end="4114" data-start="4056"&gt;Manufacturer Palo Alto believes made the actual device&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-end="4183" data-start="4115"&gt;
&lt;TD data-col-size="sm" data-end="4132" data-start="4115"&gt;&lt;STRONG data-end="4131" data-start="4117"&gt;OUI Vendor&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD data-col-size="md" data-end="4183" data-start="4132"&gt;Manufacturer associated with the NIC/MAC prefix&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="4234" data-start="4185"&gt;For example, an industrial controller could have:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;Vendor: Siemens
OUI Vendor: Intel&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="4281" data-start="4236"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-end="4324" data-start="4283"&gt;because Intel made the network interface.&lt;/P&gt;
&lt;P data-end="4510" data-start="4326"&gt;If your requirement is specifically &lt;STRONG data-end="4445" data-start="4362"&gt;“alert me when these MAC OUIs appear,” use OUI Vendor / MAC-derived information&lt;/STRONG&gt;, not simply Device Vendor.&lt;/P&gt;
&lt;P data-end="4715" data-start="4512"&gt;And one other consideration: randomized/private MAC addresses can make OUI-based detection unreliable for some Wi-Fi clients, although that's generally less of an issue with fixed-purpose IoT/OT devices.&lt;/P&gt;
&lt;P data-end="4753" data-start="4717"&gt;So conceptually, I'd build yours as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="contents"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-(--code-block-surface) corner-superellipse/1.1 overflow-clip rounded-3xl [--code-block-surface:var(--bg-elevated-secondary)] dark:[--code-block-surface:var(--composer-surface-primary)] lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;MAC/OUI
   ↓
Device Security identifies OUI Vendor
   ↓
Saved filter / custom attribute or tag
   ↓
New Device Discovery
   ↓
Custom Alert
   ↓
Email / SIEM / SOC notification&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-end="4942" data-start="4755"&gt;&amp;nbsp;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 Sep 2026 18:05:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/security-to-detect-specific-device/m-p/1263532#M2520</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2026-09-02T18:05:55Z</dc:date>
    </item>
  </channel>
</rss>

