<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to view threats, blocked activity over time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-threats-blocked-activity-over-time/m-p/469313#M102917</link>
    <description>&lt;P&gt;I am trying to understand how to view threats, malicious IPs, etc over time. For instance in the ACC tab I understand one can view threats, threat source IPs etc. I am not seeing how to view trends, for example if we want to see if there has been an increase in traffic from a certain country or threats from a certain source IP. I would like to be able to view a report and see if there were increases in a certain time frame. I am only seeing total count, a break down of information over a time would be useful. I would appreciate any help, thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Feb 2022 18:58:48 GMT</pubDate>
    <dc:creator>ccfritz</dc:creator>
    <dc:date>2022-02-28T18:58:48Z</dc:date>
    <item>
      <title>How to view threats, blocked activity over time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-threats-blocked-activity-over-time/m-p/469313#M102917</link>
      <description>&lt;P&gt;I am trying to understand how to view threats, malicious IPs, etc over time. For instance in the ACC tab I understand one can view threats, threat source IPs etc. I am not seeing how to view trends, for example if we want to see if there has been an increase in traffic from a certain country or threats from a certain source IP. I would like to be able to view a report and see if there were increases in a certain time frame. I am only seeing total count, a break down of information over a time would be useful. I would appreciate any help, thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 18:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-threats-blocked-activity-over-time/m-p/469313#M102917</guid>
      <dc:creator>ccfritz</dc:creator>
      <dc:date>2022-02-28T18:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to view threats, blocked activity over time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-threats-blocked-activity-over-time/m-p/469516#M102938</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70579"&gt;@ccfritz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You can generate a custom report of source country activity and add the date as criteria along with count to get a basic understanding of network increases it that's something that you are looking for. Historical trend information is generally something that I would offload to an external SIEM however (IE: Graylog/Splunk) to build detailed reporting dashboards however instead of the firewall's built-in reporting capability.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 15:36:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-view-threats-blocked-activity-over-time/m-p/469516#M102938</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-03-01T15:36:37Z</dc:date>
    </item>
  </channel>
</rss>

