<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive alerts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345672#M86371</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The entire list looks like web browsing (unified logs showing as such?) and as a result the botnet alerts are incorrect. Surely this is not normal behaviour?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2020 04:22:20 GMT</pubDate>
    <dc:creator>FarzanaMustafa</dc:creator>
    <dc:date>2020-08-27T04:22:20Z</dc:date>
    <item>
      <title>False positive alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345484#M86349</link>
      <description>&lt;P&gt;A very high quantity of botnet false alerts being reported on our appliance. Using 9.1.3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Botnet report alerts as noted below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Repeatedly visited (10) the same URL 216.58.199.36/&lt;/P&gt;&lt;P&gt;Repeatedly visited (30) the same URL 142.250.66.164/&lt;/P&gt;&lt;P&gt;Repeatedly visited (69) the same URL 142.250.67.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Visited malware URL tdsjsext1.life/ExtService.svc/getextparams .&lt;BR /&gt;&lt;BR /&gt;216.58.203.100 resolves to app-id “google-base”/443&lt;BR /&gt;&lt;BR /&gt;If you check the above IP addresses, you will see a common factor, it looks like this is normal behaviour for Googles ad platform?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to fix this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 00:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345484#M86349</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2020-08-26T00:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: False positive alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345557#M86360</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The botnet reports anything that is connecting directly to an IP address instead of an FQDN; while this is common in Ad networks, the firewall doesn't maintain a list of IPs that is "common" to be connecting directly due to these bad practices. The only thing that is really saying is that someone connected directly to an IP address, and doing so can be an indication of an issue.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 13:28:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345557#M86360</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-26T13:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: False positive alerts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345672#M86371</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The entire list looks like web browsing (unified logs showing as such?) and as a result the botnet alerts are incorrect. Surely this is not normal behaviour?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 04:22:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/false-positive-alerts/m-p/345672#M86371</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2020-08-27T04:22:20Z</dc:date>
    </item>
  </channel>
</rss>

