<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Real time alerts for threats? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238187#M68224</link>
    <description>&lt;P&gt;Is there such a thing with PAN?&amp;nbsp; IE if the logs generate a critical alert can is there some logic to fire an email or generate a report with the relevant information?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Nov 2018 13:18:45 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2018-11-01T13:18:45Z</dc:date>
    <item>
      <title>Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238187#M68224</link>
      <description>&lt;P&gt;Is there such a thing with PAN?&amp;nbsp; IE if the logs generate a critical alert can is there some logic to fire an email or generate a report with the relevant information?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238187#M68224</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-11-01T13:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238197#M68226</link>
      <description>&lt;P&gt;Yes.&amp;nbsp; It's found under Device Groups (in Panorama) under Objects &amp;gt; Log Forwarding.&lt;/P&gt;&lt;P&gt;Link &lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/monitoring/configure-email-alerts" target="_blank"&gt;here &lt;/A&gt;(PANOS 7.1 - it's the same in PANOS 8).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ThreatAlerts.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17423i61B31F83D73B62BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ThreatAlerts.png" alt="ThreatAlerts.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238197#M68226</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-11-01T13:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238201#M68228</link>
      <description>&lt;P&gt;Thanks..but it won't let me put anything under Email eventhough I have email profiles configured under Panorama &amp;gt; Server Profiles &amp;gt; Email.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pan-log-forward-noemail.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17425iE09941B21F9E15F9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pan-log-forward-noemail.JPG" alt="pan-log-forward-noemail.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238201#M68228</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-11-01T13:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238203#M68229</link>
      <description>&lt;P&gt;That's the Email Profile for your Panorama - not the firewalls for which it is managing policies.&amp;nbsp; Find a similar Email Server Profile under Templates &amp;gt; Device &amp;gt; Server Profiles &amp;gt; Email.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note:&amp;nbsp; the Log forwarding is in a Device Group.&amp;nbsp; The Email Profile is in the Template.&amp;nbsp; Your targets for both need to match or you will get a commit failure.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:53:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238203#M68229</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-11-01T13:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238205#M68230</link>
      <description>&lt;P&gt;Targets need to match?&amp;nbsp; I don't follow.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238205#M68230</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-11-01T13:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238206#M68231</link>
      <description>&lt;P&gt;The firewall target of your Device Group must also be in scope for the Template.&amp;nbsp; If you are using shared templates/device groups, just make sure the firewall that gets the Device Groups have templates that have an email profile with the same name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that help?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 13:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238206#M68231</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-11-01T13:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238207#M68232</link>
      <description>&lt;P&gt;Yeap!&amp;nbsp; Thanks for your help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One last question, will this be real time or do I need to schedule it to run?&amp;nbsp; I lied as I have more questions, do I need to apply this log forwarding profile to a security rule?&amp;nbsp; I already have all my logs forwarded to PANORAMA on all of my rules but I am not clear on how log profiles are applied?&amp;nbsp; Across the board or per rule?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 14:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238207#M68232</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-11-01T14:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238211#M68233</link>
      <description>&lt;P&gt;In my experience, real time.&amp;nbsp; Including the caveats that come with that:&amp;nbsp; you may be turning on an email fire-hose if you set it to email on events that you see hundreds of each minute.&amp;nbsp; Caveat emptor.&amp;nbsp; The firewall is happy to melt your mail queue if you tell it to.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 14:37:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238211#M68233</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-11-01T14:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238217#M68236</link>
      <description>&lt;P&gt;Expected, thanks for your help&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/99005"&gt;@JW6224&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 15:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238217#M68236</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2018-11-01T15:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238227#M68237</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34542"&gt;@drewdown&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;One last question, will this be real time or do I need to schedule it to run?&amp;nbsp; I lied as I have more questions, do I need to apply this log forwarding profile to a security rule?&amp;nbsp; I already have all my logs forwarded to PANORAMA on all of my rules but I am not clear on how log profiles are applied?&amp;nbsp; Across the board or per rule?&amp;nbsp;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not per-rule.&amp;nbsp; It is a log forward.&amp;nbsp; When you go to the Monitor tab, you will see several logs (Traffic, URL, Threat, etc.)&amp;nbsp; It is forwarding those log entries as you direct in the forwarding rule, when the firewall records each log entry.&amp;nbsp; Does that make sense?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 16:06:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238227#M68237</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-11-01T16:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Real time alerts for threats?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238349#M68276</link>
      <description>&lt;P&gt;I actually tried to do this with Log Correlation on Panorama.&amp;nbsp; In theory it should work great, in practice (on 8.0.9) the filter builder, and possibly the resulting filters, in that part of the GUI doesn't seem to work correctly and also emails aren't always being sent upon a match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The filter builder outputs slightly different syntax in some cases than what the rest of the system uses.&amp;nbsp; Even if it is the same filter result, I wasn't getting matches despite being able to use the same filter in the Threat Monitor and getting results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This and some reporting are some areas I really hope improvements are made in some of the newer versions.&amp;nbsp; We have a team that deals with desktop issues and I'd love to be able to send correlated event information for a possible malware infection straight to their ticket queue via email so they can know to go take a look at it.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/real-time-alerts-for-threats/m-p/238349#M68276</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-11-02T14:19:56Z</dc:date>
    </item>
  </channel>
</rss>

