<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log Forwarding for Flood event in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187723#M57082</link>
    <description>&lt;P&gt;I'm familiar with the process of setting up a log forwarding profile and attaching it to a security rule.&amp;nbsp; But how would this work for alerting on a flood event?&amp;nbsp; In a flood the attacker IP is 0.0.0.0 and the victim IP is 0.0.0.0.&amp;nbsp; This won't match any of our rules.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Nov 2017 17:35:10 GMT</pubDate>
    <dc:creator>abryantgca</dc:creator>
    <dc:date>2017-11-17T17:35:10Z</dc:date>
    <item>
      <title>Log Forwarding for Flood event</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187723#M57082</link>
      <description>&lt;P&gt;I'm familiar with the process of setting up a log forwarding profile and attaching it to a security rule.&amp;nbsp; But how would this work for alerting on a flood event?&amp;nbsp; In a flood the attacker IP is 0.0.0.0 and the victim IP is 0.0.0.0.&amp;nbsp; This won't match any of our rules.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 17:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187723#M57082</guid>
      <dc:creator>abryantgca</dc:creator>
      <dc:date>2017-11-17T17:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding for Flood event</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187749#M57083</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59794"&gt;@abryantgca&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since you could be talking about two different things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) DoS Protection Profile Flood.&lt;/P&gt;&lt;P&gt;Since the flood is recorded as a threat with a Severity rating of critical it will fall under whatever your log-forwarding profile has for that, you just need to make sure that the log-forwarding profile is assigned to the DoS Protection Profile associated with the flood.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Zone Protection Profile&lt;/P&gt;&lt;P&gt;This setting is actually pulled from the Log Setting configured for the different Zones. Within your Zones configuration you'll have an option to set a Log Setting, this is your log forwarding profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 20:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187749#M57083</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-17T20:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Log Forwarding for Flood event</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187750#M57084</link>
      <description>&lt;P&gt;Thanks for clarifying, it was the Zone Protection.&amp;nbsp; That worked.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 20:28:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-for-flood-event/m-p/187750#M57084</guid>
      <dc:creator>abryantgca</dc:creator>
      <dc:date>2017-11-17T20:28:34Z</dc:date>
    </item>
  </channel>
</rss>

