<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I Obtain the CVE in the PA event Log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78089#M42815</link>
    <description>&lt;P&gt;Try gonig to Vulmerbiliites profile and click on default profiel or any one and the open it and then click exception tab than check&amp;nbsp; boxshow signatures box like below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4029i896B5B309E38B0EE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2016-05-13 at 5.22.56 PM.png" alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4028i40F010B424B1B1A3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2016-05-13 at 5.22.56 PM.png" alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2016 23:26:45 GMT</pubDate>
    <dc:creator>clyde.franklin</dc:creator>
    <dc:date>2016-05-13T23:26:45Z</dc:date>
    <item>
      <title>Can I Obtain the CVE in the PA event Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78030#M42809</link>
      <description>&lt;P&gt;We have numerous PA firewalls that alert for vulnerabilities. I also have a product that scans for vulnerabilities in my network. The scanning device has CVE numbers in its events. The PA has PA's unique identifier in its event. Is there a way for me to pull in the CVE into the Pans threat event so I can correlate the PANs threat events to my existing vulnerability events based on CVE number?&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 04:22:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78030#M42809</guid>
      <dc:creator>Chuck555555</dc:creator>
      <dc:date>2016-05-13T04:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Obtain the CVE in the PA event Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78054#M42810</link>
      <description>&lt;P&gt;Hello, Chuck, and good morning to you sir!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First, this appears to be a question better suited for the general discussion forum as it doesn't appear to pertain to custom signatures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I would like to point out that if you click on a value populating the "NAME" column in the threat monitor, the metadata for that threat name should appear like so:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 597px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4025iD917CA4B499A29AF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CVE associated is part of this metadata. I don't believe a separate column can be created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Respectfully,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;rcole&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 12:46:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78054#M42810</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-05-13T12:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Obtain the CVE in the PA event Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78058#M42811</link>
      <description>&lt;P&gt;Hi Chuck,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Welcome to our community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can issue "configuration mode" command, like below:&lt;/P&gt;
&lt;P&gt;admin@Luciano-PA-VM# show predefined threats vulnerability [press ENTER, don't press tab or ?]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and you will get json output where you will have CVE description:&lt;/P&gt;
&lt;P&gt;vulnerability {&lt;BR /&gt; 35931 {&lt;BR /&gt; threatname "HP Data Protector OmniInet Opcode Buffer Overflow Vulnerability";&lt;BR /&gt; cve CVE-2011-1865;&lt;BR /&gt; category overflow;&lt;BR /&gt; severity high;&lt;BR /&gt; affected-host {&lt;BR /&gt; server yes;&lt;BR /&gt; }&lt;BR /&gt; default-action alert;&lt;BR /&gt; }&lt;BR /&gt; 35933 {&lt;BR /&gt; threatname "HP Data Protector OmniInet Opcode 27 Buffer Overflow Vulnerability";&lt;BR /&gt; cve CVE-2011-1865;&lt;BR /&gt; category overflow;&lt;BR /&gt; severity high;&lt;BR /&gt; affected-host {&lt;BR /&gt; server yes;&lt;BR /&gt; }&lt;BR /&gt; default-action alert;&lt;BR /&gt; }&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think this is the only way to get something usable/useful, you could prolly run a script once a day (because you don't get updates more often) and just populate your fields what is the threat ID vs. the CVE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps, AFAIK this is the only (remotely) functional way to do it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;BR /&gt;&lt;BR /&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 13:36:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78058#M42811</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-05-13T13:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Obtain the CVE in the PA event Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78063#M42812</link>
      <description>&lt;P&gt;There is not currently a mechanism that I am aware of to see the CVE in the threat log of the PA Networks devices.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might want to discuss this idea with your account team. They could tell you if a feature enhancement is in the system for this or not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 15:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78063#M42812</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2016-05-13T15:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Obtain the CVE in the PA event Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78073#M42814</link>
      <description>&lt;P&gt;Just to let you know, because this was not related to the Custom Signatures, so I moved it to General Topics.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 18:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78073#M42814</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2016-05-13T18:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Obtain the CVE in the PA event Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78089#M42815</link>
      <description>&lt;P&gt;Try gonig to Vulmerbiliites profile and click on default profiel or any one and the open it and then click exception tab than check&amp;nbsp; boxshow signatures box like below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4029i896B5B309E38B0EE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2016-05-13 at 5.22.56 PM.png" alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4028i40F010B424B1B1A3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2016-05-13 at 5.22.56 PM.png" alt="Screen Shot 2016-05-13 at 5.22.56 PM.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 23:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-obtain-the-cve-in-the-pa-event-log/m-p/78089#M42815</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-13T23:26:45Z</dc:date>
    </item>
  </channel>
</rss>

