<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Botnet Syslog in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48119#M35386</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello kadak!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the answer. I was think about send email. Really I'll do this. But, it's not the perfect way, because I'll wanted make a dashboard. With the dashboard I'll can monitoring in real time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards!&lt;/P&gt;&lt;P&gt;Lucas P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Dec 2013 12:22:21 GMT</pubDate>
    <dc:creator>lucaspassos</dc:creator>
    <dc:date>2013-12-19T12:22:21Z</dc:date>
    <item>
      <title>Botnet Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48117#M35384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a syslog that I make some monitoring dashboards and the customer want one view about all botnets in my network.&lt;/P&gt;&lt;P&gt;I had configured Palo Alto to send the logs to syslog. But I can't found the log about botnet. &lt;/P&gt;&lt;P&gt;Somewhere know how can I do this? What log that we can see the infections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Lucas Passos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 18:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48117#M35384</guid>
      <dc:creator>lucaspassos</dc:creator>
      <dc:date>2013-12-17T18:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Botnet Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48118#M35385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;Hello Lucas,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: arial,helvetica,sans-serif; font-weight: normal;"&gt;Botnet Reporting is a threat prevention feature. The PAN collates information from traffic, threat, URL logs to identify botnet-infected hosts. The report generated each day consists a list of infected hosts, description(why we believe the host is infected) and a Confidence level. You can configure the parameters in addition to the query indicating what traffic you'd like to see the botnet report on. &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;There are no Botnet logs, just predefined Botnet reports that run daily.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #3b3b3b; font-style: normal; font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #3b3b3b; font-style: normal; font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;However, you can configure botnet reports to be emailed out on daily basis according to your email server profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #3b3b3b; font-style: normal; font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;Under Monitor &amp;gt; Botnet &amp;gt; Report setting&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #3b3b3b; font-style: normal; font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-weight: normal;"&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10371_pastedImage_5.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: arial,helvetica,sans-serif; font-weight: normal;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; text-align: left; color: #333333; font-size: 13px; font-style: normal; font-family: arial,helvetica,sans-serif; font-weight: normal;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can then create report group to include that botnet report&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10372_pastedImage_6.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then create an email scheduler with email server profile to include that report group&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10374_pastedImage_8.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="247" src="https://live.paloaltonetworks.com/legacyfs/online/10373_pastedImage_7.png" style="width: 648.898px; height: 247px;" width="649" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The above process who trigger an email&amp;nbsp; (botnet report attached to it ) everyday to &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jdoe@xy.com"&gt;jdoe@xy.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since there is nothing called botnet log, we cannot forward it to any external server.&amp;nbsp; On another note, you can indeed forward your threat logs to external entities by following the document:&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3837"&gt;How to Forward Threat Logs to Syslog Server&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope thats helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Dec 2013 17:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48118#M35385</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-12-18T17:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Botnet Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48119#M35386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello kadak!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the answer. I was think about send email. Really I'll do this. But, it's not the perfect way, because I'll wanted make a dashboard. With the dashboard I'll can monitoring in real time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards!&lt;/P&gt;&lt;P&gt;Lucas P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Dec 2013 12:22:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48119#M35386</guid>
      <dc:creator>lucaspassos</dc:creator>
      <dc:date>2013-12-19T12:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Botnet Syslog</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48120#M35387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you considered the API on your PA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the botnet report is a predefined report, you can pull it using the API with a URL like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://PAFIREWALL/api/?type=report&amp;amp;reporttype=predefined&amp;amp;reportname=botnet" title="https://PAFIREWALL/api/?type=report&amp;amp;reporttype=predefined&amp;amp;reportname=botnet"&gt;https://PA_FIREWALL_IP/api/?type=report&amp;amp;reporttype=predefined&amp;amp;reportname=botnet&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that in play, all you have to do is have something pull that URL (need to add the API auth string to the request first) and change out the IP address with that of each of your firewall modules.&amp;nbsp; As long as the server (QRadar) for example, is configured to read the XML responses, you can read and act as needed on the report results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can pull the CSV's straight out as well - but that takes two requests - one to generate the report and the other to fetch the result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 21:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/botnet-syslog/m-p/48120#M35387</guid>
      <dc:creator>JohnSilvia</dc:creator>
      <dc:date>2015-02-23T21:34:30Z</dc:date>
    </item>
  </channel>
</rss>

