<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Full location of affected threat URL/filename? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32009#M23447</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes&lt;/P&gt;&lt;P&gt;It depends on application.&lt;/P&gt;&lt;P&gt;Go and browse the web.&lt;/P&gt;&lt;P&gt;Download some pdf or doc from internet for example.&lt;/P&gt;&lt;P&gt;Go and find log entry for this file.&lt;/P&gt;&lt;P&gt;And you should see referer link there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not then copy ip of other side and paste it to URL filtering log.&lt;/P&gt;&lt;P&gt;Probably as destination. For example&lt;/P&gt;&lt;P&gt;( addr.dst in 194.106.121.19 )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Jun 2015 15:45:08 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2015-06-26T15:45:08Z</dc:date>
    <item>
      <title>Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32006#M23444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Troubleshooting what I think is a false positive but the Detailed Log View (under Threats monitoring) only shows the filename and not its full location on the HD of the machine. Is there any way to find out the full location?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2015 19:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32006#M23444</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2015-06-25T19:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32007#M23445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Data filtering log.&lt;/P&gt;&lt;P&gt;Click on magnifying glass and bottom right there is url column where you can see full url.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 07:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32007#M23445</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-06-26T07:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32008#M23446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. Do you mean the magnifying glass that brings up the "Detailed Log View?" Its URL column only indicates "setup.exe" in this example, and not the full disk path. I wonder if that's available anywhere?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 15:23:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32008#M23446</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2015-06-26T15:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32009#M23447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes&lt;/P&gt;&lt;P&gt;It depends on application.&lt;/P&gt;&lt;P&gt;Go and browse the web.&lt;/P&gt;&lt;P&gt;Download some pdf or doc from internet for example.&lt;/P&gt;&lt;P&gt;Go and find log entry for this file.&lt;/P&gt;&lt;P&gt;And you should see referer link there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not then copy ip of other side and paste it to URL filtering log.&lt;/P&gt;&lt;P&gt;Probably as destination. For example&lt;/P&gt;&lt;P&gt;( addr.dst in 194.106.121.19 )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 15:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32009#M23447</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-06-26T15:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32010#M23448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case, it is *originating* from an internal machine to another, and the only URL listed is the filename without its fixed disk location. I am guessing the filename + the originating machine is as much information as it will have since that info isn't on the network info without some sort of agent on the originating machine. I'm trying to find out where on that originating machine it is located.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 15:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32010#M23448</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2015-06-26T15:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32011#M23449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So it is SMB traffic (Windows file share)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 15:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32011#M23449</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-06-26T15:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32012#M23450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it's SMB traffic. Whoops forgot to mention that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 15:54:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32012#M23450</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2015-06-26T15:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Full location of affected threat URL/filename?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32013#M23451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I doubt that you see UNC path anywhere.&lt;/P&gt;&lt;P&gt;For example you can't block traffic based on UNC path &lt;A href="https://live.paloaltonetworks.com/docs/DOC-7786"&gt;Dynamic Block Lists and UNC Server Path&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Jun 2015 05:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/full-location-of-affected-threat-url-filename/m-p/32013#M23451</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-06-27T05:30:28Z</dc:date>
    </item>
  </channel>
</rss>

