<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert mail for threat detection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312731#M80837</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I don't have Log Settings set up on my rules. I will do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just question : on my default intra-zone, I can't activate Log Settings :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="feelgood_0-1582631303454.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24064i5D42F8BD4E9F4CE9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="feelgood_0-1582631303454.png" alt="feelgood_0-1582631303454.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It can works yet ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Feb 2020 11:49:25 GMT</pubDate>
    <dc:creator>feelgood</dc:creator>
    <dc:date>2020-02-25T11:49:25Z</dc:date>
    <item>
      <title>Alert mail for threat detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312383#M80784</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to set up alert mail to prevent when my PA220 detects an threat (inboud attack for example).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured scheduled PDF reports (daily and weekly) but I want also be informed instantly when a threat is detecting ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is possible ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312383#M80784</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2020-02-21T13:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Alert mail for threat detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312424#M80790</link>
      <description>&lt;P&gt;Yes, Do you have a logging option set on ALL your rules [ including the two default inter/intra zone ones ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so on&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Objects &amp;gt; Log Forward &amp;gt; [your YourLogFowardName ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create a log forward type "Threat" with a destination of e-mail...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will probably want tor change the severity in the log filter section.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312424#M80790</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-02-21T16:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Alert mail for threat detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312464#M80792</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79471"&gt;@feelgood&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;mentioned, you probably want to set the severity filter to avoid getting an alert on every single threat; generally I would advise that people run with at least the filter (severity geq medium) which would send you an alert for all medium and higher alerts. Some people like to set the filter to ((action neq alert) or (action neq allow)) but I personally find that to be too much when configuring an email profile.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 21:40:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312464#M80792</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-21T21:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alert mail for threat detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312731#M80837</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I don't have Log Settings set up on my rules. I will do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just question : on my default intra-zone, I can't activate Log Settings :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="feelgood_0-1582631303454.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24064i5D42F8BD4E9F4CE9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="feelgood_0-1582631303454.png" alt="feelgood_0-1582631303454.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It can works yet ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 11:49:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312731#M80837</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2020-02-25T11:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Alert mail for threat detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312788#M80844</link>
      <description>&lt;P&gt;Select the rule , then find (OVERRIDE) Cog at the bottom o the page. This will allow you to change the log settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 15:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/312788#M80844</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-02-25T15:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Alert mail for threat detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/313059#M80876</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 12:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-mail-for-threat-detection/m-p/313059#M80876</guid>
      <dc:creator>feelgood</dc:creator>
      <dc:date>2020-02-26T12:19:54Z</dc:date>
    </item>
  </channel>
</rss>

