<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Changing Severity Alerts for Specific Vulnerability Severity in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/changing-severity-alerts-for-specific-vulnerability-severity/m-p/240027#M464</link>
    <description>&lt;P&gt;One of the logging capabilities allows us to provide an email for certain severity alerts.&amp;nbsp; We are getting innodated with alerts coming in from the baddies on the internet for certain types of alerts.&amp;nbsp; For instance, there is the&amp;nbsp;"Netis/Netcore Router Default Credential Remote Code Execution Vulnerability(39587)" and that is a high severity.&amp;nbsp; Since we do not use any of this equipment, this would be something we don't need to be notified about but still want to block.&amp;nbsp; We block all High/Critical seveirty, we don't want to stop blocking it but we do want to stop getting emails about this and others alike.&amp;nbsp; Is there a way for us to either change the action/alerting of a specific vulnerability?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Nov 2018 17:56:58 GMT</pubDate>
    <dc:creator>Chris_Julio</dc:creator>
    <dc:date>2018-11-15T17:56:58Z</dc:date>
    <item>
      <title>Changing Severity Alerts for Specific Vulnerability Severity</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/changing-severity-alerts-for-specific-vulnerability-severity/m-p/240027#M464</link>
      <description>&lt;P&gt;One of the logging capabilities allows us to provide an email for certain severity alerts.&amp;nbsp; We are getting innodated with alerts coming in from the baddies on the internet for certain types of alerts.&amp;nbsp; For instance, there is the&amp;nbsp;"Netis/Netcore Router Default Credential Remote Code Execution Vulnerability(39587)" and that is a high severity.&amp;nbsp; Since we do not use any of this equipment, this would be something we don't need to be notified about but still want to block.&amp;nbsp; We block all High/Critical seveirty, we don't want to stop blocking it but we do want to stop getting emails about this and others alike.&amp;nbsp; Is there a way for us to either change the action/alerting of a specific vulnerability?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 17:56:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/changing-severity-alerts-for-specific-vulnerability-severity/m-p/240027#M464</guid>
      <dc:creator>Chris_Julio</dc:creator>
      <dc:date>2018-11-15T17:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Changing Severity Alerts for Specific Vulnerability Severity</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/changing-severity-alerts-for-specific-vulnerability-severity/m-p/240059#M465</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You can use a filter with the negate option to filter out that traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cln1CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cln1CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 20:57:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/changing-severity-alerts-for-specific-vulnerability-severity/m-p/240059#M465</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-15T20:57:21Z</dc:date>
    </item>
  </channel>
</rss>

