<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Prevention inspection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13995#M10272</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnaks, That'll do panos.... That'll do&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Nov 2014 22:21:27 GMT</pubDate>
    <dc:creator>Zewwy</dc:creator>
    <dc:date>2014-11-18T22:21:27Z</dc:date>
    <item>
      <title>Threat Prevention inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13993#M10270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've really been enjoying the Palo Alto ability to update itself with threats prevention signatures almost instantly (depending on ones setup)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been checking the ACC more latly and have notice the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/16929_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll make some notes here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) This is only appearing to user who are using the Global Protect to VPN into the corporate network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) the Victim host is our SharePoint FE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) We currently have an issue where constant Event ID 1 are populated on the SharePoint FE due to a miss configured Performance Point Service which (AFAIK) as been removed from every aspect of our SharePoint (we currently don't use scorecard, etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) I don't know if these two issue are related in some way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is as follows is there any way I can get more details on each hit of this threat event? It'd be nice to click on the session and it displayed each session and time the event occurred/got triggered. Since these events are being done by legit users while remoteing in I'm not majorly concerned since I'm sure it has something to with the complex inner SharePoint permission structure (Even posting on TechNet, no one was able to tell me how to query any web parts that might be using performance point to track that event..)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But even for future threat sessions it be nice to see when they occurred to help track who was doing what when.. etc... please and thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 19:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13993#M10270</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2014-11-18T19:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13994#M10271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;you have to filter and find these threats on Monitor/threat logs&lt;/P&gt;&lt;P&gt;so each session detail is there.if it is not enough , you may open packet capture for the related security profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 20:04:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13994#M10271</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-18T20:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention inspection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13995#M10272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnaks, That'll do panos.... That'll do&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 22:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-prevention-inspection/m-p/13995#M10272</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2014-11-18T22:21:27Z</dc:date>
    </item>
  </channel>
</rss>

