<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious login attempt found on PA. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170489#M54050</link>
    <description>&lt;P&gt;Except for console logins, there obviously is no IP address&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2017 11:35:48 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-08-08T11:35:48Z</dc:date>
    <item>
      <title>Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170480#M54047</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a situation where someone tried to access Palo Alto and failed to login as the authentication was not granted. Any idea where i can go and see what was the source IP and location etc. A bit of forensics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions most welcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Imran&lt;/P&gt;&lt;P&gt;(Brighton)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 11:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170480#M54047</guid>
      <dc:creator>imranshahid</dc:creator>
      <dc:date>2017-08-08T11:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170487#M54048</link>
      <description>&lt;P&gt;PA-3020 shows failed auths in /Monitor/System.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event = auth-fail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this shows the ip address of the failed auth.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 11:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170487#M54048</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-08T11:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170488#M54049</link>
      <description>&lt;P&gt;this shows the source ip address of the failed auth.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 11:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170488#M54049</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-08T11:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170489#M54050</link>
      <description>&lt;P&gt;Except for console logins, there obviously is no IP address&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 11:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/170489#M54050</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-08T11:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171821#M54286</link>
      <description>&lt;P&gt;so how would you find the source IP ? Any comments please feel free&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 09:51:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171821#M54286</guid>
      <dc:creator>imranshahid</dc:creator>
      <dc:date>2017-08-16T09:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171842#M54291</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It says from:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="auth logs.PNG" style="width: 797px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10801iBB1F3180F788868F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="auth logs.PNG" alt="auth logs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can only see this info if the attempts were initiated to the mgmt interface. If the&amp;nbsp;user was trying to get access over the data-plane interface, then check intra-zone&amp;nbsp;traffic (if logging is enabled) filtering based on the destination Palo&amp;nbsp;ip address as well as destination port 443.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 12:17:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171842#M54291</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-16T12:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171849#M54293</link>
      <description>&lt;P&gt;you will also get auth-fail logs if the attempt was made on a dataplane management profile &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 13:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171849#M54293</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-16T13:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious login attempt found on PA.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171850#M54294</link>
      <description>&lt;P&gt;Nice! I thought system log just includes mgmt interface attempts&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 13:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-login-attempt-found-on-pa/m-p/171850#M54294</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-16T13:36:51Z</dc:date>
    </item>
  </channel>
</rss>

