<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using XML API to enumerate virus (antivirus) signatures in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-xml-api-to-enumerate-virus-antivirus-signatures/m-p/9281#M6788</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the panxapi (from @ksteves) I'm able to enumerate all the threats (scan, vulnerability, phone-home), but I'm not able to find an xpath I can use to enumerate information about the antivirus signatures. By way of example, I can see that in my log output each virus hit appears to have a name and and entry number:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;,Virus/Win32.WGeneric.aecnl(2920072),&amp;lt;/snip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to be able to scrape ALL the name/number combinations from the PA regularly so I can create entries in my SIEM (and thus see these messages in the console). Does anyone know if this is possible, and if so would you share the xpath you used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jesse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Dec 2013 19:56:46 GMT</pubDate>
    <dc:creator>wfleitz</dc:creator>
    <dc:date>2013-12-12T19:56:46Z</dc:date>
    <item>
      <title>Using XML API to enumerate virus (antivirus) signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-xml-api-to-enumerate-virus-antivirus-signatures/m-p/9281#M6788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the panxapi (from @ksteves) I'm able to enumerate all the threats (scan, vulnerability, phone-home), but I'm not able to find an xpath I can use to enumerate information about the antivirus signatures. By way of example, I can see that in my log output each virus hit appears to have a name and and entry number:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;snip&amp;gt;,Virus/Win32.WGeneric.aecnl(2920072),&amp;lt;/snip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to be able to scrape ALL the name/number combinations from the PA regularly so I can create entries in my SIEM (and thus see these messages in the console). Does anyone know if this is possible, and if so would you share the xpath you used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jesse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 19:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-xml-api-to-enumerate-virus-antivirus-signatures/m-p/9281#M6788</guid>
      <dc:creator>wfleitz</dc:creator>
      <dc:date>2013-12-12T19:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Using XML API to enumerate virus (antivirus) signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-xml-api-to-enumerate-virus-antivirus-signatures/m-p/9282#M6789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please post this question in the Dev center, that is the primary support location for the XML API and you are much more likely to get a reply sooner.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 16:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-xml-api-to-enumerate-virus-antivirus-signatures/m-p/9282#M6789</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2013-12-14T16:36:20Z</dc:date>
    </item>
  </channel>
</rss>

