<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow - firewallEvent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/163944#M53005</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67727"&gt;@evanskie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I&amp;nbsp;&lt;EM&gt;think&lt;/EM&gt; this would likely make more sense if it just called 'flow' what it trully is refering to, a session. I could be wrong on that though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I'm right that would make it essentially be&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 = Flow created&lt;/P&gt;&lt;P&gt;2 = Flow deleted&lt;/P&gt;&lt;P&gt;3 = Flow denied&lt;/P&gt;&lt;P&gt;4 = Flow alert&lt;/P&gt;&lt;P&gt;5 = Flow update&lt;/P&gt;&lt;P&gt;Would actually mean&lt;/P&gt;&lt;P&gt;1) Session Created&lt;/P&gt;&lt;P&gt;2) Session Deleted. &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Session Denied.&lt;/P&gt;&lt;P&gt;4) &amp;nbsp;? If I would have to guess I would say this triggers if a DoS profile is tripped, I would have to test this out to be sure though. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) Session switched from Active to Drop due to something like an applicaiton change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The document is included in all of the 7.1 administration guides and I would assume 8.0 as well, but no further description was provided in the 7.0 and 7.1 administration guides when I looked.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2017 22:41:22 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-06-29T22:41:22Z</dc:date>
    <item>
      <title>Netflow - firewallEvent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/163926#M53003</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;what does the content of the firewallEvent field mean? Is there a better documentation than this document?&lt;/P&gt;&lt;P&gt;-&amp;gt; &lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/reports-and-logging/netflow-templates" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/reports-and-logging/netflow-templates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Especially what is the difference between "Flow created" and "Flow deleted"?&lt;/P&gt;&lt;P&gt;Is "Flow created" a flow with a duration shorter than a defined timeout and "Flow deleted" a very short-lived flow?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Flow updated" seems to be a long lasting flow exported in separate parts, but the document states:&lt;/P&gt;&lt;P&gt;"the session state changed from active to deny". I am unsure about that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When would "Flow alerted" be generated? It never pops up in my collector software.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 22:05:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/163926#M53003</guid>
      <dc:creator>evanskie</dc:creator>
      <dc:date>2017-06-29T22:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow - firewallEvent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/163944#M53005</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67727"&gt;@evanskie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I&amp;nbsp;&lt;EM&gt;think&lt;/EM&gt; this would likely make more sense if it just called 'flow' what it trully is refering to, a session. I could be wrong on that though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I'm right that would make it essentially be&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 = Flow created&lt;/P&gt;&lt;P&gt;2 = Flow deleted&lt;/P&gt;&lt;P&gt;3 = Flow denied&lt;/P&gt;&lt;P&gt;4 = Flow alert&lt;/P&gt;&lt;P&gt;5 = Flow update&lt;/P&gt;&lt;P&gt;Would actually mean&lt;/P&gt;&lt;P&gt;1) Session Created&lt;/P&gt;&lt;P&gt;2) Session Deleted. &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Session Denied.&lt;/P&gt;&lt;P&gt;4) &amp;nbsp;? If I would have to guess I would say this triggers if a DoS profile is tripped, I would have to test this out to be sure though. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) Session switched from Active to Drop due to something like an applicaiton change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The document is included in all of the 7.1 administration guides and I would assume 8.0 as well, but no further description was provided in the 7.0 and 7.1 administration guides when I looked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 22:41:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/163944#M53005</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-29T22:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow - firewallEvent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/164011#M53016</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my understanding a unique flow is determined by the tuple SRC-Ip/SRC-Port and DST-Ip/DST-Port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I analyzed the flow data in my environment (ELK-Stack) and there are only entries of unique flows which are tagged either with "Flow create" or "Flow deleted". So there must be an other explanation for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For "Flow update" I can see multiple entries for the same flow exported about every 15 minutes (long lasting SSH-Connections).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Flow denied" is clear: this flow was dropped by the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Someone else some ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 07:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-firewallevent/m-p/164011#M53016</guid>
      <dc:creator>evanskie</dc:creator>
      <dc:date>2017-06-30T07:59:41Z</dc:date>
    </item>
  </channel>
</rss>

