<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat email alert throttling in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288826#M76884</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's what I was suspecting. Just wanted to make sure I did not miss any options...&lt;/P&gt;</description>
    <pubDate>Tue, 17 Sep 2019 17:14:38 GMT</pubDate>
    <dc:creator>CHKlomp</dc:creator>
    <dc:date>2019-09-17T17:14:38Z</dc:date>
    <item>
      <title>Threat email alert throttling</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288657#M76869</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We're setup to email threat alerts, and are getting an email for every alert generated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there a way to throuttle the emails? Particularly for a single threat that is blocked, we don't need 60 emails/min for all the blocks. It would suffice for the first 10 per 10 min interval. When you get the first 10 emails, you know someone is hammering your system. It suffices to know that in 10 min, they are still at it, if they would be...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or is this more SIEM territory?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you, Chris Klomp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 22:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288657#M76869</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2019-09-16T22:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Threat email alert throttling</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288679#M76870</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48132"&gt;@CHKlomp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is more of a SIEM function and isn't something you can natively limit on the firewall at all. Since your requirements sound relatively low if you are just looking for alert limiting, you could get away with installing Graylog on a machine you have laying around using that if you don't already have a SIEM setup.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 02:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288679#M76870</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-17T02:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Threat email alert throttling</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288826#M76884</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's what I was suspecting. Just wanted to make sure I did not miss any options...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 17:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-email-alert-throttling/m-p/288826#M76884</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2019-09-17T17:14:38Z</dc:date>
    </item>
  </channel>
</rss>

