<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to view the &amp;quot;Hits&amp;quot; of my Vulnerability Protection Rule in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/150754#M4</link>
    <description>&lt;P&gt;Thinking through it as&amp;nbsp;I read back my own post. Is the rule I created applicable to my objective?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;STRONG&gt;My Objective&lt;/STRONG&gt;&lt;/FONT&gt;:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;Instead of me “manually” changing the default action for all “Critical” severity signatures as they&amp;nbsp;are delivered by Palo Alto&amp;nbsp;, I want a rule to do this for me automatically. Meaning, once a Signature update arrives (Vulnerability signature), all those that are “Critical” should have an Action of Drop, since I already set a rule that is applied in my Vulnerability profile. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or this rule is more on the "Threat" as it comes in, and not on the "Vulnerability Signature"? Sorry for branching out my question, I just want to nail this down really hard. Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2017 06:21:01 GMT</pubDate>
    <dc:creator>Eugene_Alejandro</dc:creator>
    <dc:date>2017-04-03T06:21:01Z</dc:date>
    <item>
      <title>How to view the "Hits" of my Vulnerability Protection Rule</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/150753#M3</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hello Everyone,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I am quite new to PA, so i would need your suggestion about this.&lt;/P&gt;&lt;P&gt;I created a Vulnerability Protection Rule wherein my goal is once a Signature update arrives (Vulnerability signature), all those that are “Critical” would have an automatic Action of &lt;STRONG&gt;Drop.&lt;/STRONG&gt;&amp;nbsp;And that&amp;nbsp;I dont need to manually set the action for "Critical" threat one-by-one inside the "Exceptions" tab.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Here's the rule i created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CriticalVulnerability.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8603iE3C767C07A4CD06D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CriticalVulnerability.jpg" alt="CriticalVulnerability.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please advise if there is a custom report that I can set or a section where i can see the running "hits" for this rule? Just like how the Logs in the "Monitoring" tab display the running traffic, threats, etc etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much!!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 03:27:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/150753#M3</guid>
      <dc:creator>Eugene_Alejandro</dc:creator>
      <dc:date>2017-04-03T03:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to view the "Hits" of my Vulnerability Protection Rule</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/150754#M4</link>
      <description>&lt;P&gt;Thinking through it as&amp;nbsp;I read back my own post. Is the rule I created applicable to my objective?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;STRONG&gt;My Objective&lt;/STRONG&gt;&lt;/FONT&gt;:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;Instead of me “manually” changing the default action for all “Critical” severity signatures as they&amp;nbsp;are delivered by Palo Alto&amp;nbsp;, I want a rule to do this for me automatically. Meaning, once a Signature update arrives (Vulnerability signature), all those that are “Critical” should have an Action of Drop, since I already set a rule that is applied in my Vulnerability profile. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or this rule is more on the "Threat" as it comes in, and not on the "Vulnerability Signature"? Sorry for branching out my question, I just want to nail this down really hard. Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 06:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/150754#M4</guid>
      <dc:creator>Eugene_Alejandro</dc:creator>
      <dc:date>2017-04-03T06:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to view the "Hits" of my Vulnerability Protection Rule</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/160266#M18</link>
      <description>If you look at the threat windows under monitor you can you can filter for ( subtype eq vulnerability ) once you have that filtered if you know what rule(s) the vulnerability profile is set to you can then click on the magnifier on the left and look at the details to get more information about the Threat Name that was blocked and the severity. Or depending on the version you are on you could look under the ACC Tab and check the Threat activity and filter by the critical severity and see the rule/count there. I hope that helps if not let me know.</description>
      <pubDate>Thu, 08 Jun 2017 19:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-view-the-quot-hits-quot-of-my-vulnerability-protection/m-p/160266#M18</guid>
      <dc:creator>murphyj</dc:creator>
      <dc:date>2017-06-08T19:07:47Z</dc:date>
    </item>
  </channel>
</rss>

