<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different Threat ID for Data Filtering and Wildfire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/different-threat-id-for-data-filtering-and-wildfire/m-p/151656#M50196</link>
    <description>&lt;P&gt;I couldn't find a list via Google, but if it helps any, you can at least add the ID field to the Monitor -&amp;gt; Data Filtering logs to see the threat IDs for the entries.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.JPG" style="width: 247px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8682i7C5CD805FD83F596/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and the Wildfire log does have a field for Threat ID (not to be confused with ID), which appears to mesh with the data filtering ID&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.JPG" style="width: 260px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8684i27D369DB6536E1DF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;if you feel like putting in the work, you can use the 'show threat id' command in the CLI, but you have to specify the ID, so you basically need to manually scan each number, tho I suppose there could be some level of automation if it was really worth the investment to you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Apr 2017 09:52:04 GMT</pubDate>
    <dc:creator>bradk14</dc:creator>
    <dc:date>2017-04-07T09:52:04Z</dc:date>
    <item>
      <title>Different Threat ID for Data Filtering and Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-threat-id-for-data-filtering-and-wildfire/m-p/151644#M50193</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once upon a time, I stumbled across a page with all the threat ID's used for Data Filtering.&lt;BR /&gt;&lt;BR /&gt;From what I remember"PKG File Detected(52152)" &amp;nbsp;is the threat name and ID used when the firewall sees a PKG file. &amp;nbsp;&lt;SPAN&gt;Windows Executable (EXE) (52020) is when the firewall detects a windows executable.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I am slightly puzzled to see this threat ID used for a wildfire report in Splunk. From my previous experience, wildfire alerts had a different set of threat ID. I would like to know the following:&lt;BR /&gt;&lt;BR /&gt;1. Does anybody know where is the list of threat ID used for the DATA Filtering events?&lt;/P&gt;&lt;P&gt;2. Why would the wildfire report have the threat ID of a DATA Filtering event?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;Weng Seng.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 08:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-threat-id-for-data-filtering-and-wildfire/m-p/151644#M50193</guid>
      <dc:creator>wengsengtam</dc:creator>
      <dc:date>2017-04-07T08:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Different Threat ID for Data Filtering and Wildfire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-threat-id-for-data-filtering-and-wildfire/m-p/151656#M50196</link>
      <description>&lt;P&gt;I couldn't find a list via Google, but if it helps any, you can at least add the ID field to the Monitor -&amp;gt; Data Filtering logs to see the threat IDs for the entries.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.JPG" style="width: 247px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8682i7C5CD805FD83F596/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and the Wildfire log does have a field for Threat ID (not to be confused with ID), which appears to mesh with the data filtering ID&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.JPG" style="width: 260px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8684i27D369DB6536E1DF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;if you feel like putting in the work, you can use the 'show threat id' command in the CLI, but you have to specify the ID, so you basically need to manually scan each number, tho I suppose there could be some level of automation if it was really worth the investment to you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 09:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-threat-id-for-data-filtering-and-wildfire/m-p/151656#M50196</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-07T09:52:04Z</dc:date>
    </item>
  </channel>
</rss>

