<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Traffic Pattern / behavior based detection is possible in PaloAlto as in the Cisco,. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-traffic-pattern-behavior-based-detection-is-possible-in/m-p/38387#M28115</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no traffic baselining/anomaly detection available in the product at this time. But you could feed traffic logs into splunk and analyse from there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Sep 2013 07:30:24 GMT</pubDate>
    <dc:creator>gafrol</dc:creator>
    <dc:date>2013-09-25T07:30:24Z</dc:date>
    <item>
      <title>Is Traffic Pattern / behavior based detection is possible in PaloAlto as in the Cisco,.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-traffic-pattern-behavior-based-detection-is-possible-in/m-p/38386#M28114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is Traffic Pattern / behavior based detection is possible in PaloAlto as in the Cisco,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Cisco it works as fallows,.if we have enabled traffic sensor for particular time period it will calculate the percentage of traffic based on protocols as shown below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP - 30%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FTP - 20%&amp;nbsp;&amp;nbsp; HTTPS- 50%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; and this information will be used in future traffic analysis, for eg : If HTTP traffic goes above or below the 30% then it send alerts to administrator and same for the FTP (above or below 20% and HTTPS 50%).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 05:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-traffic-pattern-behavior-based-detection-is-possible-in/m-p/38386#M28114</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2013-09-25T05:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is Traffic Pattern / behavior based detection is possible in PaloAlto as in the Cisco,.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-traffic-pattern-behavior-based-detection-is-possible-in/m-p/38387#M28115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no traffic baselining/anomaly detection available in the product at this time. But you could feed traffic logs into splunk and analyse from there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 07:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-traffic-pattern-behavior-based-detection-is-possible-in/m-p/38387#M28115</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-09-25T07:30:24Z</dc:date>
    </item>
  </channel>
</rss>

