<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS - set up packet logging in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22674#M16565</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mikand for you reply, is there someone who can clarify us on this ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Nov 2012 18:17:53 GMT</pubDate>
    <dc:creator>Samir.Belkessam</dc:creator>
    <dc:date>2012-11-16T18:17:53Z</dc:date>
    <item>
      <title>IPS - set up packet logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22672#M16563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if there is a possibility to collect some packets before and after the packet that trigged the attack signature&lt;/P&gt;&lt;P&gt;it will be helpful in case of troubleshooting and confirm if this attack is a false positive or real attack( knowing that this option is available from other vendors )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;&lt;P&gt;Samir.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2012 18:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22672#M16563</guid>
      <dc:creator>Samir.Belkessam</dc:creator>
      <dc:date>2012-11-15T18:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - set up packet logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22673#M16564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you setup a profile for the IPS in Objects -&amp;gt; Security Profiles -&amp;gt; Vulnerability Protection you can define if packet capture should be performed or not (either globally like a group of threatid's or specific threatid's).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant find any info in the manual if packets from before the packet that triggered the attack signature will be part of this pcap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2012 09:18:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22673#M16564</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-16T09:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - set up packet logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22674#M16565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mikand for you reply, is there someone who can clarify us on this ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2012 18:17:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ips-set-up-packet-logging/m-p/22674#M16565</guid>
      <dc:creator>Samir.Belkessam</dc:creator>
      <dc:date>2012-11-16T18:17:53Z</dc:date>
    </item>
  </channel>
</rss>

