<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive threat in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/284490#M76312</link>
    <description>&lt;P&gt;Thank you all for the response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had file blocking in place...&lt;SPAN&gt;disabled the file blocking and this has resolved the issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2019 00:46:46 GMT</pubDate>
    <dc:creator>FarzanaMustafa</dc:creator>
    <dc:date>2019-08-22T00:46:46Z</dc:date>
    <item>
      <title>False positive threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/283634#M76266</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PA-3020 is falsely identifying some adobe-creative-cloud-base traffic as being a threat.&amp;nbsp; I can't add an exception for this as the log view does not contain a threat ID as it normally would for a threat.&amp;nbsp; All of my dynamic updates are up to date.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The URL filtering profile is set to ‘alert’ for computer-and-internet-info (I have most of the categories set to ‘alert’).&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The rule is set to ‘application default’ for the ports.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How to resolve this issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21039iE21CBB3B7E03356B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21040iC16598DF657A845C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 03:59:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/283634#M76266</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-08-20T03:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: False positive threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/283716#M76271</link>
      <description>&lt;P&gt;If you can get a PCAP of the traffic.&amp;nbsp; Open a ticket with support.&amp;nbsp; They'll review the PCAP and get the signature updated to not alert on this false positive.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 12:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/283716#M76271</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-08-20T12:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: False positive threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/284465#M76306</link>
      <description>&lt;P&gt;I have not ever seen an application signature being false postive for a threat.&lt;/P&gt;&lt;P&gt;Now, it could be information inside the flow, using the app signature, but definitely not the app signature itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the URL category set to alert, then I would want to see a screen capture of the security profile group (if any) for your rule.&lt;/P&gt;&lt;P&gt;I am thinking you may have&amp;nbsp; multiple URL filtering profiles and one of them is set to block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we would need see screen captures to show us this info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 21:24:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/284465#M76306</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-21T21:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: False positive threat</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/284490#M76312</link>
      <description>&lt;P&gt;Thank you all for the response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had file blocking in place...&lt;SPAN&gt;disabled the file blocking and this has resolved the issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 00:46:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-threat/m-p/284490#M76312</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-08-22T00:46:46Z</dc:date>
    </item>
  </channel>
</rss>

