<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email alerts,. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/139160#M48077</link>
    <description>&lt;P&gt;Doing it through reporting will require that you either run it every x minutes if you want the same day's data. When you run a scheduled report, the best you'll get is yesterday's data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how I did it years ago when we had several SMTP servers sending us malicious email attachments with the same message body.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What you could do is create a data filtering profile searching for a data pattern X in application SMTP.&lt;/LI&gt;&lt;LI&gt;Then create a firewall policy with SMTP as the application type and port 25 as the service port in the policy then apply your Data Filtering profile (and anything else SMTP should have for a profile like AV etc. too!).&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Put this above your regular SMTP permit policies.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Don't forget you won't see a match if you aren't decrypting the SSL when using encrypted SMTP so add that also if needed.&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Now on that firewall policy make sure your logging destination includes an email forwarding profile so you get an alert everytime it is matched.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Tue, 24 Jan 2017 19:20:17 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2017-01-24T19:20:17Z</dc:date>
    <item>
      <title>Email alerts,.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/29666#M21675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to generate email alert for particular event and send it to particular email id?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example: If any data found (in attachment or in email) which is defined in DATA Pattern send alert to&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ABC@test.com"&gt;ABC@test.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If any file is blocked then send alert to&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:XYZ@test.com"&gt;XYZ@test.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 11:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/29666#M21675</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2013-08-28T11:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Email alerts,.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/29667#M21676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not directly supported but can do other things like log forwarding traffic log hits that 2 specific rule written.&lt;/P&gt;&lt;P&gt;Also look at &lt;A href="https://live.paloaltonetworks.com/message/4216"&gt;Email notification per specific threat&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 12:30:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/29667#M21676</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-28T12:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Email alerts,.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/29668#M21677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use the below method. The only difference is that you will not get the emails instantly, but only at the time the scheduled email reports are sent out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create a custom report for the file blocking / data filtering events&lt;/P&gt;&lt;P&gt;&lt;IMG alt="data filtering.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7968_data filtering.JPG.jpg" style="width: 620px; height: 346px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add this custom report to a report group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="data-filtering-2.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7969_data-filtering-2.JPG.jpg" style="width: 620px; height: 475px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use this report group under an email scheduler&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="data-filtering-3.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7970_data-filtering-3.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can play around with the override email addresses, depending upon who the recipient of the email shall be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 13:02:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/29668#M21677</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-28T13:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Email alerts,.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/139160#M48077</link>
      <description>&lt;P&gt;Doing it through reporting will require that you either run it every x minutes if you want the same day's data. When you run a scheduled report, the best you'll get is yesterday's data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how I did it years ago when we had several SMTP servers sending us malicious email attachments with the same message body.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What you could do is create a data filtering profile searching for a data pattern X in application SMTP.&lt;/LI&gt;&lt;LI&gt;Then create a firewall policy with SMTP as the application type and port 25 as the service port in the policy then apply your Data Filtering profile (and anything else SMTP should have for a profile like AV etc. too!).&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Put this above your regular SMTP permit policies.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Don't forget you won't see a match if you aren't decrypting the SSL when using encrypted SMTP so add that also if needed.&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Now on that firewall policy make sure your logging destination includes an email forwarding profile so you get an alert everytime it is matched.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 24 Jan 2017 19:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-alerts/m-p/139160#M48077</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-01-24T19:20:17Z</dc:date>
    </item>
  </channel>
</rss>

