<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automated Correlation Engine - Will it look at log entries from before the upgrade to PAN-OS 7? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/automated-correlation-engine-will-it-look-at-log-entries-from/m-p/18663#M13608</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I can tell - it appears that it will only look at log events entered after the upgrade to PAN-OS 7.&amp;nbsp; The reason I say this is that I have a correlated events entry for a host that was 'beaconing' to a known malware URL(after the upgrade) but similar url events that already existed did not result in a new entry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Aug 2015 19:19:47 GMT</pubDate>
    <dc:creator>bgirdner</dc:creator>
    <dc:date>2015-08-07T19:19:47Z</dc:date>
    <item>
      <title>Automated Correlation Engine - Will it look at log entries from before the upgrade to PAN-OS 7?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automated-correlation-engine-will-it-look-at-log-entries-from/m-p/18662#M13607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have logs going to Panorama from Firewalls running PAN-OS 6.1.5, I recently upgraded Panorama from 6.1.5 to 7.0.1.&amp;nbsp; Does anyone know if it will look at the old log events in the correlation engine or if it will only look at new ones coming in?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to test and confirm that the automated correlation engine is working?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Aug 2015 16:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automated-correlation-engine-will-it-look-at-log-entries-from/m-p/18662#M13607</guid>
      <dc:creator>bgirdner</dc:creator>
      <dc:date>2015-08-07T16:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Automated Correlation Engine - Will it look at log entries from before the upgrade to PAN-OS 7?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/automated-correlation-engine-will-it-look-at-log-entries-from/m-p/18663#M13608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I can tell - it appears that it will only look at log events entered after the upgrade to PAN-OS 7.&amp;nbsp; The reason I say this is that I have a correlated events entry for a host that was 'beaconing' to a known malware URL(after the upgrade) but similar url events that already existed did not result in a new entry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Aug 2015 19:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/automated-correlation-engine-will-it-look-at-log-entries-from/m-p/18663#M13608</guid>
      <dc:creator>bgirdner</dc:creator>
      <dc:date>2015-08-07T19:19:47Z</dc:date>
    </item>
  </channel>
</rss>

