<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Top 20 Outbound IP Report in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/top-20-outbound-ip-report/m-p/289989#M647</link>
    <description>&lt;P&gt;We have a new security director and I have been tasked with created a few reports about IP traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The request for for the following:&lt;/P&gt;&lt;P&gt;-Top 20 outbound IPs that are NOT in the DNS cache&lt;/P&gt;&lt;P&gt;-Top 20 outbound IPs by data sent&lt;/P&gt;&lt;P&gt;-Top 20 outbound IPs by connection time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been working on a custom report for this, but I'm having trouble editing out the DNS cached IPs - there doesnt seem to be an option. I really just need a way (if possible) to remove cached entries, and just list IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2019 14:25:38 GMT</pubDate>
    <dc:creator>NathanV</dc:creator>
    <dc:date>2019-09-25T14:25:38Z</dc:date>
    <item>
      <title>Top 20 Outbound IP Report</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/top-20-outbound-ip-report/m-p/289989#M647</link>
      <description>&lt;P&gt;We have a new security director and I have been tasked with created a few reports about IP traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The request for for the following:&lt;/P&gt;&lt;P&gt;-Top 20 outbound IPs that are NOT in the DNS cache&lt;/P&gt;&lt;P&gt;-Top 20 outbound IPs by data sent&lt;/P&gt;&lt;P&gt;-Top 20 outbound IPs by connection time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been working on a custom report for this, but I'm having trouble editing out the DNS cached IPs - there doesnt seem to be an option. I really just need a way (if possible) to remove cached entries, and just list IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 14:25:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/top-20-outbound-ip-report/m-p/289989#M647</guid>
      <dc:creator>NathanV</dc:creator>
      <dc:date>2019-09-25T14:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Top 20 Outbound IP Report</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/top-20-outbound-ip-report/m-p/291487#M653</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm not sure you can do this with the PAN. You might need a SIEM for this however if you are referring to the DNS cache of the PAN, you might be out of luck on that. You'll have to get that from the DNS server the PAN is using for lookups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 18:22:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/top-20-outbound-ip-report/m-p/291487#M653</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-10-04T18:22:03Z</dc:date>
    </item>
  </channel>
</rss>

