<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone using save/load filter optins under Monitor tab? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132720#M47107</link>
    <description>&lt;P&gt;I only have one filter saved, but it's one I use all the time while in the Unified Log Viewer. &amp;nbsp;It's:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; (action neq allow) and (action neq alert) and (app neq teredo) and (app neq quic) and (addr in x.x.x.x)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This one is great because it will show you if something's being blocked for a specific IP address, inbound or outbound, URL or Threat, or File Type, etc. &amp;nbsp;I put the teredo/quic apps in there because they're blocked &amp;amp; logged right now and I don't want to see those in this specific query. &amp;nbsp;I also use the more generic "addr in x.x.x.x" instead of specifying source or destination address... because I want to see hits where x.x.x.x was the source (usually outbound connections, URLs, etc.) but also want x.x.x.x as the destination too (for blocked files, threats, etc.) &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2016 03:08:05 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2016-12-14T03:08:05Z</dc:date>
    <item>
      <title>Anyone using save/load filter optins under Monitor tab?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132551#M47086</link>
      <description>&lt;P&gt;Out of curiosity is anyone using Save Filter and Load Filter options under Monitor tab and find them user friendly?&lt;/P&gt;&lt;P&gt;I have mentioned to Palo&amp;nbsp;representatives few times that filter field should have droppdown history like browser address bars have but they always suggest to go with save/load option that i really dislike &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2016 03:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132551#M47086</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-12-13T03:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using save/load filter optins under Monitor tab?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132622#M47094</link>
      <description>&lt;P&gt;The only time I use them is usually really long queries&amp;nbsp;that generally and even then they have to include specific threat identification ids before I use them. Usually I just forget that they are even there and move on. I see PAs point with not wanting a drop down history though; I run a lot of query's&amp;nbsp;that I will likely never need again and wouldn't want them constantly&amp;nbsp;popping up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2016 13:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132622#M47094</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-13T13:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using save/load filter optins under Monitor tab?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132696#M47106</link>
      <description>&lt;P&gt;Yeah issue is that usually you are working on something and have filter almost set.&lt;/P&gt;&lt;P&gt;And then colleque comes and asks "hey please check this for me real quick...".&lt;/P&gt;&lt;P&gt;Notepad helps out in those cases but there must be easier way.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2016 21:37:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132696#M47106</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-12-13T21:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using save/load filter optins under Monitor tab?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132720#M47107</link>
      <description>&lt;P&gt;I only have one filter saved, but it's one I use all the time while in the Unified Log Viewer. &amp;nbsp;It's:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; (action neq allow) and (action neq alert) and (app neq teredo) and (app neq quic) and (addr in x.x.x.x)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This one is great because it will show you if something's being blocked for a specific IP address, inbound or outbound, URL or Threat, or File Type, etc. &amp;nbsp;I put the teredo/quic apps in there because they're blocked &amp;amp; logged right now and I don't want to see those in this specific query. &amp;nbsp;I also use the more generic "addr in x.x.x.x" instead of specifying source or destination address... because I want to see hits where x.x.x.x was the source (usually outbound connections, URLs, etc.) but also want x.x.x.x as the destination too (for blocked files, threats, etc.) &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2016 03:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-using-save-load-filter-optins-under-monitor-tab/m-p/132720#M47107</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-12-14T03:08:05Z</dc:date>
    </item>
  </channel>
</rss>

