<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scanning network flow using file name in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50198#M36967</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes you can do that, very usefull for auditing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Maybe upload logs to syslog server and make a script for sending an alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Aug 2013 10:31:12 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2013-08-20T10:31:12Z</dc:date>
    <item>
      <title>Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50191#M36960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any know an opportunity to scan network flow with PaloAlto to find files by file name? Eg.: i entered "angry tiger" and i find all files (including all file types) with that name sent over the network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 13:52:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50191#M36960</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-19T13:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50192#M36961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check these links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3904"&gt;https://live.paloaltonetworks.com/docs/DOC-3904&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/23749#23749"&gt;https://live.paloaltonetworks.com/message/23749#23749&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/10273#10273"&gt;https://live.paloaltonetworks.com/message/10273#10273&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/11919#11919"&gt;https://live.paloaltonetworks.com/message/11919#11919&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:31:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50192#M36961</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-19T14:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50193#M36962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We see that you are looking for certain text and you are receiving all files with all file types. If there is a filter to be made for certain file types we will have to use the file blocking profile as explained below.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3094" style="font-size: 10pt; line-height: 1.5em;"&gt;https://live.paloaltonetworks.com/docs/DOC-3094&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can also create custom vulnerability by creating custom signature for matching a certain pattern of text in files so that the PAN can search for these texts and when matches logs with the custom vulnerability on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 14:33:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50193#M36962</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-08-19T14:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50194#M36963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for answers. So as i understand, no way to find file using file name. Or anyone has other ideas? &lt;/P&gt;&lt;P&gt;Let me explain more what i want: If someone sent a file: angry_tiger.doc or angry_tiger.mp3, or angry_tiger.avi, or angry_tiger.*(any file type). Can i some how find that file using file name "angry_tiger"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 07:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50194#M36963</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-20T07:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50195#M36964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please follow below mentioned discussion for more info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/3553#3553" style="font-size: 10pt; line-height: 1.5em;"&gt;https://live.paloaltonetworks.com/message/3553#3553&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hope it &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 07:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50195#M36964</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-08-20T07:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50196#M36965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to search file name, you ave to go through data filtering profile.&lt;/P&gt;&lt;P&gt;The easiest way to do it is to use regex? With this method you can search all what you want.&lt;/P&gt;&lt;P&gt;Eg: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4860"&gt;https://live.paloaltonetworks.com/docs/DOC-4860&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just keep in mind that you can't search string with size&amp;nbsp; under 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 08:37:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50196#M36965</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-20T08:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50197#M36966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found one solution: i must log all file types using File Blocking profile (File Type -&amp;gt; any, Action -&amp;gt; alert) and then in a Data Filtering log i can find file using file name. Not ideal, but works &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 10:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50197#M36966</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-20T10:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Scanning network flow using file name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50198#M36967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes you can do that, very usefull for auditing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Maybe upload logs to syslog server and make a script for sending an alert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 10:31:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scanning-network-flow-using-file-name/m-p/50198#M36967</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-20T10:31:12Z</dc:date>
    </item>
  </channel>
</rss>

