<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Correlation log subtype action always allowed? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348294#M86725</link>
    <description>&lt;P&gt;Is the correlation log_subtype action always allowed? It creates a bit of confusion when the action on the actual event was blocked, but the correlation action shows allowed. Just looking for clarification.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Sep 2020 16:14:33 GMT</pubDate>
    <dc:creator>MikeSangray2019</dc:creator>
    <dc:date>2020-09-10T16:14:33Z</dc:date>
    <item>
      <title>Correlation log subtype action always allowed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348294#M86725</link>
      <description>&lt;P&gt;Is the correlation log_subtype action always allowed? It creates a bit of confusion when the action on the actual event was blocked, but the correlation action shows allowed. Just looking for clarification.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 16:14:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348294#M86725</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-10T16:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation log subtype action always allowed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348444#M86732</link>
      <description>&lt;P&gt;Are you looking at the Panorama logs?&lt;/P&gt;
&lt;P&gt;Can you upload screen captures from devices, so we can visually see what you are explaining to us?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 02:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348444#M86732</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-11T02:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation log subtype action always allowed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348622#M86752</link>
      <description>&lt;P&gt;No, actually the PA logs don't display Action for the correlation events like you see for Traffic, Threats, etc. I'm seeing the Action as 'allowed' in Splunk logs. So all correlation events have the action 'allowed'. Just ends up being misleading when reading reports.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 15:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlation-log-subtype-action-always-allowed/m-p/348622#M86752</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2020-09-11T15:43:52Z</dc:date>
    </item>
  </channel>
</rss>

