<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic System alerts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344099#M86098</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I am getting system alerts in my firewall below is the error:-&lt;/P&gt;&lt;P&gt;PAN OS - 9.0.6&lt;/P&gt;&lt;DIV&gt;Disabled applications in vsys1: cip-ethernet-ip-disable-io cip-ethernet-ip-disable-sfc cip-ethernet-ip-enable-io cip-ethernet-ip-enable-sfc cip-ethernet-ip-read-mod-write cip-ethernet-ip-read-tag cip-ethernet-ip-read-tag-frag cip-ethernet-ip-run cip-ethernet-ip-stop cip-ethernet-ip-test-mode cip-ethernet-ip-write-tag cip-ethernet-ip-write-tag-frag dingtalk-file-transfer jandi pfcp philips-ecg retrospect-backup siemens-s7-comm-plus-download siemens-s7-comm-plus-upload.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;NOTE: I have checked the all application are disable in Application DB&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Below is the current Version for Content ID&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Application Version&lt;/TD&gt;&lt;TD&gt;8305-6248 (08/14/20)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Threat Version&lt;/TD&gt;&lt;TD&gt;8305-6248 (08/14/20)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Antivirus Version&lt;/TD&gt;&lt;TD&gt;3441-3952 (08/15/20)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Could you please give any suggestion on this.&lt;/DIV&gt;</description>
    <pubDate>Sun, 16 Aug 2020 10:19:58 GMT</pubDate>
    <dc:creator>Joshan_Lakhani</dc:creator>
    <dc:date>2020-08-16T10:19:58Z</dc:date>
    <item>
      <title>System alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344099#M86098</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I am getting system alerts in my firewall below is the error:-&lt;/P&gt;&lt;P&gt;PAN OS - 9.0.6&lt;/P&gt;&lt;DIV&gt;Disabled applications in vsys1: cip-ethernet-ip-disable-io cip-ethernet-ip-disable-sfc cip-ethernet-ip-enable-io cip-ethernet-ip-enable-sfc cip-ethernet-ip-read-mod-write cip-ethernet-ip-read-tag cip-ethernet-ip-read-tag-frag cip-ethernet-ip-run cip-ethernet-ip-stop cip-ethernet-ip-test-mode cip-ethernet-ip-write-tag cip-ethernet-ip-write-tag-frag dingtalk-file-transfer jandi pfcp philips-ecg retrospect-backup siemens-s7-comm-plus-download siemens-s7-comm-plus-upload.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;NOTE: I have checked the all application are disable in Application DB&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Below is the current Version for Content ID&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Application Version&lt;/TD&gt;&lt;TD&gt;8305-6248 (08/14/20)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Threat Version&lt;/TD&gt;&lt;TD&gt;8305-6248 (08/14/20)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Antivirus Version&lt;/TD&gt;&lt;TD&gt;3441-3952 (08/15/20)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Could you please give any suggestion on this.&lt;/DIV&gt;</description>
      <pubDate>Sun, 16 Aug 2020 10:19:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344099#M86098</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-16T10:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: System alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344136#M86105</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130663"&gt;@Joshan_Lakhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To fix this you need to go to Device,Log Setting, System&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create&amp;nbsp; a filter for example&lt;/P&gt;
&lt;P&gt;(severity eq high) and (eventid neq Disabled apps)&lt;/P&gt;
&lt;P&gt;or&amp;nbsp;&lt;/P&gt;
&lt;P&gt;not ( description contains 'Disabled applications')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is your log forwarding profile which is sending you the system alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 17:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344136#M86105</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-16T17:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: System alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344142#M86111</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;I didnt configure the log forwarding , it is showing alerts in systems&lt;BR /&gt;Any issue if i ignore this or i need to take some action.&lt;BR /&gt;Please suggest.&lt;/DIV&gt;</description>
      <pubDate>Sun, 16 Aug 2020 19:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344142#M86111</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-16T19:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: System alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344144#M86113</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can ignore this these alerts.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 19:19:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344144#M86113</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-16T19:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: System alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344163#M86116</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130663"&gt;@Joshan_Lakhani&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Whoever setup your firewall has them setup so that the new app-ids are disabled when you download a new content update. While this can prevent issues rising from new app-ids being identified, it's something that you would eventually want to bring in so that your firewall can identify all of the new applications PAN has added.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So while these alerts can be ignored, I would definitely make the new signatures active in your next maintenance window and simply verify that the new applications don't cause any issues in your current rulebase.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 03:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alerts/m-p/344163#M86116</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-17T03:19:17Z</dc:date>
    </item>
  </channel>
</rss>

