<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log filters nested and/or problems. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205601#M60346</link>
    <description>&lt;P&gt;Sorry about the comment but there seems to be little or no documentation to creating filters and common logic does not seem to work. I am a forum contributor [mostly answering questions] on a wide number of forums for many different subjects and a&amp;nbsp;moderator on 3 automotive forums so I do offer my time freely to people also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But nobody seems to have ever had a problem, searched high and low, &amp;nbsp;which leads me to wonder if people bother?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's counter productive being alerted to a bunch of stuff that we want to ignore, can't see the wood from the trees.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Mar 2018 09:48:49 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2018-03-15T09:48:49Z</dc:date>
    <item>
      <title>Log filters nested and/or problems.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205085#M60245</link>
      <description>&lt;P&gt;Is there a proper guide to filter wrtiting and nesting????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying as hard as I can but the Palo does nto seem to like basic logic for searching&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basicaly the below should alert if the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Medium or higher,&amp;nbsp;&lt;/P&gt;&lt;P&gt;threat 40031 except if the destiantion is&amp;nbsp;192.168.10.140.&lt;/P&gt;&lt;P&gt;Not for threat 30664&lt;/P&gt;&lt;P&gt;Not for threat 37610&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(severity geq medium) and&amp;nbsp;&lt;/P&gt;&lt;P&gt;(&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ((addr.dst notin 192.168.10.140) and (threatid eq 40031))&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; or&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;(threatid neq 30664)&lt;/P&gt;&lt;P&gt;&amp;nbsp; or&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (threatid neq 37610)&lt;/P&gt;&lt;P&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried all manaer of different groupings to try and get it to work but it simply does nto seem to understand.. Getting very frustrated with it!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205085#M60245</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-03-13T12:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log filters nested and/or problems.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205351#M60296</link>
      <description>&lt;P&gt;Anyone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or does nobody look at their threats?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 09:22:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205351#M60296</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-03-14T09:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Log filters nested and/or problems.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205460#M60321</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;"or does nobody look at their threats".&lt;/P&gt;&lt;P&gt;I'm sorry,&amp;nbsp;I didn't realize that a bunch of people who volunteer&amp;nbsp;their time had a requirement to answer your question in less than 24 hours.&lt;/P&gt;&lt;P&gt;I'll give you a hint; your going about setting up the query wrong, and if properly formated it's pretty easy to get it filtered to what you're looking for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 20:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205460#M60321</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-14T20:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Log filters nested and/or problems.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205498#M60336</link>
      <description>&lt;P&gt;Just a "like" for &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;'s post is not enough. I thought I need to write it here: this answer is simply great!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205498#M60336</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-14T22:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Log filters nested and/or problems.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205601#M60346</link>
      <description>&lt;P&gt;Sorry about the comment but there seems to be little or no documentation to creating filters and common logic does not seem to work. I am a forum contributor [mostly answering questions] on a wide number of forums for many different subjects and a&amp;nbsp;moderator on 3 automotive forums so I do offer my time freely to people also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But nobody seems to have ever had a problem, searched high and low, &amp;nbsp;which leads me to wonder if people bother?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's counter productive being alerted to a bunch of stuff that we want to ignore, can't see the wood from the trees.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 09:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/205601#M60346</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-03-15T09:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Log filters nested and/or problems.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/340177#M85390</link>
      <description>&lt;P&gt;Landed on this thread looking for this same solution, the proper syntax to build a nested filter similar to the example by the OP. This thread is marked as solved, but no solution is posted. Am I missing something?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 21:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-filters-nested-and-or-problems/m-p/340177#M85390</guid>
      <dc:creator>eventcore</dc:creator>
      <dc:date>2020-07-22T21:22:59Z</dc:date>
    </item>
  </channel>
</rss>

