<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question About Categorizing Domains to Suppress Correlated Events in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-categorizing-domains-to-suppress-correlated/m-p/1231561#M124549</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/727052043"&gt;@L.Cartooms&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;These events are point in time, so the past events would not clear from the logs once the domain is categorized. It would simply suppress the event from being generated again since it's no longer unknown.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jun 2025 21:10:39 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-06-11T21:10:39Z</dc:date>
    <item>
      <title>Question About Categorizing Domains to Suppress Correlated Events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-categorizing-domains-to-suppress-correlated/m-p/1231520#M124546</link>
      <description>&lt;P data-start="167" data-end="174"&gt;Hi all,&lt;/P&gt;
&lt;P data-start="176" data-end="251"&gt;We are using Palo Alto firewalls in our network, running PAN-OS 10.2.12-h6.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="253" data-end="487"&gt;When navigating to &lt;STRONG data-start="272" data-end="334"&gt;Monitor &amp;gt; Automated Correlation Engine &amp;gt; Correlated Events&lt;/STRONG&gt;, we often see entries like the following:&amp;nbsp;&lt;EM data-start="379" data-end="487"&gt;“Host repeatedly visited uncategorized domain (20 times), and performed EXE downloads from these domains.”&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P data-start="489" data-end="629"&gt;I would like to flag these domains or IP addresses as safe or categorize them so that I no longer receive alerts for known, trusted domains.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="631" data-end="962"&gt;Typically, I categorize domains using the &lt;A href="https://urlfiltering.paloaltonetworks.com/" target="_blank"&gt;Palo Alto Networks URL filtering - Test A Site&lt;/A&gt;&amp;nbsp;page. My question is:&lt;BR data-start="745" data-end="748" /&gt;If I categorize a domain through that page, will it affect how these events are generated? Specifically, will the correlated events disappear if the domains are categorized as benign through the URL filtering tool?&lt;/P&gt;
&lt;P data-start="964" data-end="996"&gt;&lt;BR /&gt;Thanks in advance for your help.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 10:00:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-categorizing-domains-to-suppress-correlated/m-p/1231520#M124546</guid>
      <dc:creator>L.Cartooms</dc:creator>
      <dc:date>2025-06-11T10:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Categorizing Domains to Suppress Correlated Events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-categorizing-domains-to-suppress-correlated/m-p/1231561#M124549</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/727052043"&gt;@L.Cartooms&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;These events are point in time, so the past events would not clear from the logs once the domain is categorized. It would simply suppress the event from being generated again since it's no longer unknown.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 21:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-categorizing-domains-to-suppress-correlated/m-p/1231561#M124549</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-06-11T21:10:39Z</dc:date>
    </item>
  </channel>
</rss>

