<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Complete session captures in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31953#M23401</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are refering to the actual data in packets, then no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jun 2010 22:33:49 GMT</pubDate>
    <dc:creator>swhyte</dc:creator>
    <dc:date>2010-06-03T22:33:49Z</dc:date>
    <item>
      <title>Complete session captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31950#M23398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In an attempt to displace a SNORT environment, with a PAN implementation for monitoring ( at this stage only ),&lt;/P&gt;&lt;P&gt;we need to be able to replicate complete session captures for forensic's ( internal security, police etc ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although its possible to capture packets for false positive reasons, how would I go about storing ( most likly off the appliance )&lt;/P&gt;&lt;P&gt;packet captures so they can be reviewed as sessions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SteveRPCAP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 20:33:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31950#M23398</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2010-06-01T20:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Complete session captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31951#M23399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Katana,&lt;/P&gt;&lt;P&gt;while you are able to do packet captures on specific applications and threats on the Paloalto device, those packet captures are limited to just the first couple of packets. I assume that is not what you are looking for.&lt;/P&gt;&lt;P&gt;We can do packet filters, but once again the size would be limited. These captures are primarily for troubleshooting. From what you have described it seems you would like a full dump of all packets for all sessions that come accross the Paloalto device. Currently do not do this. But that is why we have the traffic logs which are very detailed with session info. You can in turn have the traffic logs sent to a syslog server if you desire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 22:21:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31951#M23399</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-06-01T22:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Complete session captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31952#M23400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will the traffic logs contain packet information though? Thats the key decider, as its needed for potential legal forensics.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 02:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31952#M23400</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2010-06-03T02:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Complete session captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31953#M23401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are refering to the actual data in packets, then no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 22:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31953#M23401</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-06-03T22:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Complete session captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31954#M23402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this was for a specific instance, the device can do session captures but it is not something you would leave on for all traffic going through the device. It would be targeted at tracking specific, suspect flows in the network for a brief period of time. For full network recording, a dedicated capture product would be necessary.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 00:38:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31954#M23402</guid>
      <dc:creator>mjacobsen</dc:creator>
      <dc:date>2010-06-04T00:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Complete session captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31955#M23403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about session packet capture for specific regular expressions / templates in the data patterns filters. can I perform only this action?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 16:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/complete-session-captures/m-p/31955#M23403</guid>
      <dc:creator>alexs</dc:creator>
      <dc:date>2010-08-10T16:13:33Z</dc:date>
    </item>
  </channel>
</rss>

