<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Details in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142654#M48572</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The exempt profile means that someone made an exception for this threat to NOT be monitored by the profile in the list&lt;/P&gt;
&lt;P&gt;so any security policy where this profile is used will not hit on this threat&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the profile is used in internal policy or if the threat i 'to be expected' due to how your TLS infrastructure is set up, it may not be sonething to worry about... best is to figure out who set it and why &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend to have at least a few rules in the AntiSpyware (and AV and threat) profiles to take different approaches to each severity&lt;/P&gt;
&lt;P&gt;i usually have all kinds of bells and whistles (block-ip, extended packetcapture) for critical and high, less bells for medium and low, and simply alerting for informational , i touch on this in this video &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;A href="https://www.youtube.com/watch?v=oUdqQSRyMis&amp;amp;t=10m" target="_blank"&gt;Tutorial: Configuring Your Security Policy &lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2017 08:26:15 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-02-13T08:26:15Z</dc:date>
    <item>
      <title>Threat Details</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142584#M48561</link>
      <description>&lt;P&gt;H&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="used in current.png" style="width: 585px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7731i559D6BE3212093D5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="used in current.png" alt="used in current.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What is Exempt profile here ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since severity is informational , Do we need to &amp;nbsp;care about this ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;What if we don't want &amp;nbsp;alert &amp;nbsp;or any action &amp;nbsp;if the severity is informational ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anti spyware profile.png" style="width: 770px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7732i2BC71010DBDDF75E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="anti spyware profile.png" alt="anti spyware profile.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it good practice just one rule in an antispyware profile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 15:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142584#M48561</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-02-12T15:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Details</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142654#M48572</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11223"&gt;@sib2017&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The exempt profile means that someone made an exception for this threat to NOT be monitored by the profile in the list&lt;/P&gt;
&lt;P&gt;so any security policy where this profile is used will not hit on this threat&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the profile is used in internal policy or if the threat i 'to be expected' due to how your TLS infrastructure is set up, it may not be sonething to worry about... best is to figure out who set it and why &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend to have at least a few rules in the AntiSpyware (and AV and threat) profiles to take different approaches to each severity&lt;/P&gt;
&lt;P&gt;i usually have all kinds of bells and whistles (block-ip, extended packetcapture) for critical and high, less bells for medium and low, and simply alerting for informational , i touch on this in this video &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;A href="https://www.youtube.com/watch?v=oUdqQSRyMis&amp;amp;t=10m" target="_blank"&gt;Tutorial: Configuring Your Security Policy &lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 08:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142654#M48572</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-13T08:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Details</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142664#M48574</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks reaper .You mean this threat was never monitored by the spyware profile which is used in my security rules 1 ...10 (for example),&lt;BR /&gt;So how can I add or delete from this exempted list ?&lt;BR /&gt;If this threat was exempted in this profile , how the PA did an action (reset-both) in the list as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa-suspicious.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7751i2DB95C8185DD958B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa-suspicious.png" alt="pa-suspicious.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 09:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142664#M48574</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-02-13T09:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Details</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142681#M48575</link>
      <description>&lt;P&gt;ah wait, i made a booboo&lt;/P&gt;
&lt;P&gt;that first screenshot you showed is the log info, not the profile info of that threat&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the LOG detail view you can check that box next to the profile to add an exception for that threat to that profile&lt;/P&gt;
&lt;P&gt;to take it out you need to go into the profile and remove the threatID from the exceptions tab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but uhm... your action is set to alert in the profile while the policy is reset both, is this the same profile ?&lt;/P&gt;
&lt;P&gt;if you have a profile with only 1 rule set to alert, nothing should be blocked&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 10:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142681#M48575</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-13T10:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Details</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142701#M48580</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Sorry I am little confused .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"in the LOG detail view you can check that box next to the profile to add an exception for that threat ".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;if you are talking aboot the first pic in my post , I can add only ip address &amp;nbsp; .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That means i can exempt only ip address there ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So in my case It was not exempted .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"your action is set to alert in the profile while the policy is reset both, is this the same profile ?&lt;/P&gt;&lt;P&gt;if you have a profile with only 1 rule set to alert, nothing should be blocked "&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No ,it was " reset-both ", Then i Changed to &amp;nbsp;alert &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 14:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142701#M48580</guid>
      <dc:creator>sib2017</dc:creator>
      <dc:date>2017-02-13T14:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Details</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142843#M48604</link>
      <description>&lt;P&gt;ok, sorry for the confusion!&amp;nbsp; let's start from the beginning &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the LOG view, you can open the threat details. you can add exceptions in here based on the IP address or the profile&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exempt profiles.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="exempt profiles.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this view simply allows you to add an exception for the IP involved or the whole profile, so you don't need to go into the objects tab, find the profile, go to the exceptions tab, try to remember the threat ID and then add an exception.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vulnerability profile.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="vulnerability profile.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope i made it more clear &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 08:52:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-details/m-p/142843#M48604</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-14T08:52:20Z</dc:date>
    </item>
  </channel>
</rss>

