<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor &amp;gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To &amp;quot;# Of Sessions&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38101#M27905</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ability to search through events and notify the admin when the events exceed a certain threshold is typically performed by a SIM/SIEM tool.&amp;nbsp; We offer integration with SIM/SIEM vendors listed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you like to see this feature within the Palo Alto firewall, please submit a feature request to your local Palo Alto SE.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 May 2012 19:34:35 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-05-16T19:34:35Z</dc:date>
    <item>
      <title>Monitor &gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To "# Of Sessions"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38096#M27900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&amp;nbsp; Via the Monitor page, I'm trying to build a log query, to report upon all threats regarded as critical within the last 24 hours that held / conducted a minimum of 12 (twelve) sessions.&amp;nbsp; I've got the first 2 (two) filtering parameters - my "critical" vulnerability sensitivity; and my time frame eq. last 24 hours.&amp;nbsp; However I'm "stuck", with respect to setting the Minimum Number of Sessions criteria:&amp;nbsp; I just cannot seem to figure out the appropriate filter.&amp;nbsp; So I sure hope you all can provide me some help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 18:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38096#M27900</guid>
      <dc:creator>IMgrtrU</dc:creator>
      <dc:date>2012-05-02T18:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor &gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To "# Of Sessions"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38097#M27901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...It is possible that a user may retrieve the same threat multiple times via the same tcp/udp session.&amp;nbsp; We offer the 'count' field to reflect the number of times we saw the threat.&amp;nbsp; You can sort by 'count' to see the threat events in decreasing order but we don't have a filter criteria for the count value.&amp;nbsp; You could export the report and keep those events where the count is 12 or greater.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 15:34:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38097#M27901</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-03T15:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor &gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To "# Of Sessions"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38098#M27902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like it was said before we donot have the filter criteria for gettting the threats encountered in last 24 hours that conducted a minimum of 12 sessions for a critical severity.&lt;/P&gt;&lt;P&gt;As far a I understand, the closest we can acheive in your case is filter through the session ID and/or the threat id and monitor that threat ID consistently.&lt;/P&gt;&lt;P&gt;To do that, please ,look at the attachement, capture-session-id.PNG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 May 2012 21:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38098#M27902</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-05-06T21:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor &gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To "# Of Sessions"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38099#M27903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; `&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 19:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38099#M27903</guid>
      <dc:creator>IMgrtrU</dc:creator>
      <dc:date>2012-05-16T19:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor &gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To "# Of Sessions"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38100#M27904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically what I'm requesting here, are simply 'fundamental components' for a&amp;nbsp; daily threat report log. Surely, this isn't the first time one of Palo&amp;nbsp; Alto's customers has requested a means by which to filter out the&amp;nbsp; hundreds, even thousands, of "one hit wonders" that regularly attempt to infiltrate their firewalls on a daily basis, in order to fous on the ones that are engaging in many-multiple, repeated sessions (e.g., indic. possible DoS, etcetera)?&amp;nbsp; That is, I can't be the 1st to request a filter&amp;nbsp; criteria for the count value?&amp;nbsp; Can I?&amp;nbsp; Really?...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 19:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38100#M27904</guid>
      <dc:creator>IMgrtrU</dc:creator>
      <dc:date>2012-05-16T19:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor &gt; Logs, Add Log Filter:  Is there a Filtering Criterion Equiv.-To "# Of Sessions"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38101#M27905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ability to search through events and notify the admin when the events exceed a certain threshold is typically performed by a SIM/SIEM tool.&amp;nbsp; We offer integration with SIM/SIEM vendors listed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1418"&gt;https://live.paloaltonetworks.com/docs/DOC-1418&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you like to see this feature within the Palo Alto firewall, please submit a feature request to your local Palo Alto SE.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 19:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitor-gt-logs-add-log-filter-is-there-a-filtering-criterion/m-p/38101#M27905</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-16T19:34:35Z</dc:date>
    </item>
  </channel>
</rss>

