<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Paloalto Threat Details - Signatures in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71426#M40785</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38543"&gt;@ajrockn﻿&lt;/a&gt;&amp;nbsp;can you tell which field in the threat log, you are referring to ?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2016 03:03:10 GMT</pubDate>
    <dc:creator>syadav</dc:creator>
    <dc:date>2016-01-22T03:03:10Z</dc:date>
    <item>
      <title>Paloalto Threat Details - Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71404#M40780</link>
      <description>&lt;P&gt;Could someone tell me when a signature gets detected in paloalto under Logs | Threat what &lt;EM&gt;&lt;STRONG&gt;None: &lt;/STRONG&gt;means?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thanks!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 22:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71404#M40780</guid>
      <dc:creator>ajrockn</dc:creator>
      <dc:date>2016-01-21T22:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto Threat Details - Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71426#M40785</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38543"&gt;@ajrockn﻿&lt;/a&gt;&amp;nbsp;can you tell which field in the threat log, you are referring to ?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 03:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71426#M40785</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-22T03:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto Threat Details - Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71459#M40802</link>
      <description>Its showing under the monitor tab | Logs | Threat and then under the Name column.  Is this what your asking?</description>
      <pubDate>Fri, 22 Jan 2016 16:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71459#M40802</guid>
      <dc:creator>ajrockn</dc:creator>
      <dc:date>2016-01-22T16:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto Threat Details - Signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71461#M40804</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38543"&gt;@ajrockn﻿&lt;/a&gt;&amp;nbsp; The "None:" prefix seem to indicate the Threats (and corres. Thread ID) for domains which are identified (as suspicious) by&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;"Wildfire content signatures"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; The range is as follows :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Wildfire Suspicious DNS Signatures:&amp;nbsp;3800000 - 4000000&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Threat-Articles/Threat-ID-Ranges-in-the-Palo-Alto-Networks-Content-Database/ta-p/59969" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Threat-Articles/Threat-ID-Ranges-in-the-Palo-Alto-Networks-Content-Database/ta-p/59969&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hence "None:" prefix &amp;nbsp;seems to be a notation placeholder for this threat ID range.You should be able to confirm this by your observation of the IDs in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 16:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-threat-details-signatures/m-p/71461#M40804</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-22T16:43:55Z</dc:date>
    </item>
  </channel>
</rss>

