<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DoS Protection Logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dos-protection-logs/m-p/50005#M36798</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a DoS policy setup with both an aggregate and a classified DoS profile to protect a webserver and you see flood logs in the Threat Tab.. is it possible to tell whether or not the flood matched on the aggregate or the classifed DoS profile while splitting those into two separate DoS policies?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Aug 2014 18:40:05 GMT</pubDate>
    <dc:creator>SDorsey</dc:creator>
    <dc:date>2014-08-14T18:40:05Z</dc:date>
    <item>
      <title>DoS Protection Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dos-protection-logs/m-p/50005#M36798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a DoS policy setup with both an aggregate and a classified DoS profile to protect a webserver and you see flood logs in the Threat Tab.. is it possible to tell whether or not the flood matched on the aggregate or the classifed DoS profile while splitting those into two separate DoS policies?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 18:40:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dos-protection-logs/m-p/50005#M36798</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-08-14T18:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: DoS Protection Logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dos-protection-logs/m-p/50006#M36799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mackwage,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat logs for Flood will show the attacker IP address if generated by the Classified policy/rule and will show 0.0.0.0 as the attacker IP address if generated by an Aggregate policy/rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 23:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dos-protection-logs/m-p/50006#M36799</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2014-08-16T23:42:53Z</dc:date>
    </item>
  </channel>
</rss>

