<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exempt alerting for specific threat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194867#M58266</link>
    <description>&lt;P&gt;Thanks you guys, We hope to upgrade to 8 soon&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2018 20:15:00 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2018-01-11T20:15:00Z</dc:date>
    <item>
      <title>Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194693#M58226</link>
      <description>&lt;P&gt;We have an open wifi network and do see lot of coinhive spyware threat alerts. Recently a user genrated in excess 30000 email alerts for&amp;nbsp;CoinHive JavaScript Detection. We don't want to block the user and also the external IP is not single one. Firewall is set to reset-bot on detection. We just don't want to see this email alert, is there a workaround to disable&amp;nbsp;alert on a specific spyware.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 19:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194693#M58226</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-01-10T19:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194717#M58232</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes there is. Just use the exception tab to filter the one you dont want to see out. Set it something lower and change the action.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13191i138E7947055FF094/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 22:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194717#M58232</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-10T22:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194736#M58241</link>
      <description>&lt;P&gt;How would you change the severity of threat under exceptions? SMTP Alerts are set for anything medium to critical.&lt;/P&gt;&lt;P&gt;Just to mention this is for antispyware although it should be similar to vulnerability protection.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 22:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194736#M58241</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-01-10T22:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194739#M58243</link>
      <description>&lt;P&gt;Sorry, that is where my fingers were quicker than my brain. You are correct the severity cannot be changed. If you have a SIEM you can just use it for the alerts and silence the PAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 22:57:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194739#M58243</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-10T22:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194740#M58244</link>
      <description>&lt;P&gt;PAN-OS 8.0 introduced "Filtered Log Forwarding".&amp;nbsp; This would allow you to further "tweak" the rule that generates e-mail notifications.&amp;nbsp; You could easily exempt certain events from generating e-mails, regardless of severity.&amp;nbsp; Read more about it here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Community-Blog/Make-more-sense-using-filtered-log-forwarding/ba-p/146395" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Community-Blog/Make-more-sense-using-filtered-log-forwarding/ba-p/146395&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Tutorial-Filtered-Log-Forwarding/ta-p/145950" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tutorials/Tutorial-Filtered-Log-Forwarding/ta-p/145950&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 23:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194740#M58244</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-01-10T23:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194867#M58266</link>
      <description>&lt;P&gt;Thanks you guys, We hope to upgrade to 8 soon&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 20:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/194867#M58266</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-01-11T20:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Exempt alerting for specific threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/599191#M119172</link>
      <description>&lt;P&gt;Where would one do this in PANOS 11.X?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 15:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exempt-alerting-for-specific-threat/m-p/599191#M119172</guid>
      <dc:creator>ThomasBezak</dc:creator>
      <dc:date>2024-10-01T15:37:45Z</dc:date>
    </item>
  </channel>
</rss>

