<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20913#M15277</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sandeep,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I´m able to post my screenshots.&lt;/P&gt;&lt;P&gt;First from ACC:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ACC.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5645_ACC.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Second from Monitor:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Monitor.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5646_Monitor.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see in the Threatlogs, the same type of Spyware´s severity is "Informational". Since Friday afternoon suddenly it is "Medium".&lt;/P&gt;&lt;P&gt;In ACC it was always shown with Severity "Medium"&lt;/P&gt;&lt;P&gt;Maybe there was an update in the last days?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Feb 2013 07:16:47 GMT</pubDate>
    <dc:creator>Alex_Graser</dc:creator>
    <dc:date>2013-02-18T07:16:47Z</dc:date>
    <item>
      <title>ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20910#M15274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;currently we have a Test-device from PaloAlto for evaluation (PA-5020, PANOS 5.0.2, AV-Sig 946-1309, App&amp;amp;Threats-Version 357-1692, URL-Filter 4044).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I took a look at Threat Prevention Summary in ACC and saw a few Hits "Trojan-Ransom.foreign:madeleine.adclear.net" ID=4091550 with Severity "Medium".&lt;/P&gt;&lt;P&gt;Then I was searching in ThreatLogs and filterd to show only events with severity mediu, high or critical. First I was wondering why I didn´t see the hits which were shown in ACC but then I applied another filter, this time to show only the Attacker (which i got also from ACC) and with this filter I found the hit in the ThreatLog.&lt;/P&gt;&lt;P&gt;BUT: in ThreatLog this Hit was with severity "Informational".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I´m wondering why is the severity different in ACC from that in ThreatLog? I assume the Severity comes from the Signature itself, so it should be the same severity in ACC as well as in ThreatLogs. Or am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It´s important for me to understand, because I have AntiSpyware-Profile which does a PacketCapture on Severity from Medium to Critical. Since the ThreatLog shows Severity "Informational" no capture was taken.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints on this would be usefull for me!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 12:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20910#M15274</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2013-02-15T12:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20911#M15275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACC and the threat logs should represent the same information. I have checked my lab device and it is working as expected as shown below. &lt;IMG alt="Screen Shot 2013-02-15 at 9.42.08 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5630_Screen Shot 2013-02-15 at 9.42.08 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2013-02-15 at 9.42.23 AM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5631_Screen Shot 2013-02-15 at 9.42.23 AM.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be possible for you to attach a screenshot of yours ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 17:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20911#M15275</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-02-15T17:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20912#M15276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I will take screenshots and will post it on monday.&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 19:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20912#M15276</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2013-02-15T19:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20913#M15277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sandeep,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I´m able to post my screenshots.&lt;/P&gt;&lt;P&gt;First from ACC:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ACC.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5645_ACC.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Second from Monitor:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Monitor.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5646_Monitor.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see in the Threatlogs, the same type of Spyware´s severity is "Informational". Since Friday afternoon suddenly it is "Medium".&lt;/P&gt;&lt;P&gt;In ACC it was always shown with Severity "Medium"&lt;/P&gt;&lt;P&gt;Maybe there was an update in the last days?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 07:16:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20913#M15277</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2013-02-18T07:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20914#M15278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it the same threatid in both cases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get no hits at all in threat vault when searching for Trojan-Ransom.foreign:medeleine.adclear.net (or part of that name) - and yes I did try to search in all dbs (vuln, spyware, virus).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 09:32:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20914#M15278</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-18T09:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20915#M15279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is the same threatid (id 4091550) in both cases!&lt;/P&gt;&lt;P&gt;I also get no hit when searching the db´s. BTW, its type is shown as "Spyware" in both ACC and Threatlogs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 10:26:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20915#M15279</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2013-02-18T10:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20916#M15280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe, it´s because ThreatDatabase states "Database reflects antivirus version &lt;STRONG&gt;947&lt;/STRONG&gt; and threats version &lt;STRONG&gt;356&lt;/STRONG&gt;.", but our PA-5020 runs App&amp;amp;Threats DB Version 357-1693?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 10:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20916#M15280</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2013-02-18T10:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACC shows Threat Hit with Severity as Medium while ThreatLogs shows Severity as Informational</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20917#M15281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ThreatDatabase now reflects antivirus version &lt;STRONG&gt;954&lt;/STRONG&gt; and threats version &lt;STRONG&gt;358&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;But I still can´t find ID 4091550.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has an idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alex.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2013 09:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/acc-shows-threat-hit-with-severity-as-medium-while-threatlogs/m-p/20917#M15281</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2013-02-21T09:01:30Z</dc:date>
    </item>
  </channel>
</rss>

