<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why I see no logs for DoS policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387879#M90441</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp; I checked and as you can see below on setting the filter to that IP i can see Syn cookies are sent. But why does it not show in logs is my problem. I know its not much but its still higher than alarm rate of 1 and should show in threat logs as cookie sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter match destination X.X.X.X&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;show counter global filter delta yes packet-filter yes aspect dos&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 7.374 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;flow_dos_syncookie_cookie_sent 16 1 info flow dos TCP SYN cookies: cookies sent, aggregate profile/zone&lt;BR /&gt;flow_dos_syncookie_ack_rcv 25 1 info flow dos TCP SYN cookies: ACKs to cookies received, aggregate profile/zone&lt;BR /&gt;flow_dos_cl_syncookie_ack_rcv 4 0 info flow dos TCP SYN cookies: ACKs to cookies received, classified profile&lt;BR /&gt;flow_dos_rule_allow_under_rate 78 6 info flow dos Packets allowed: Rate within thresholds of DoS policy&lt;BR /&gt;flow_dos_rule_match 78 6 info flow dos Packets matched DoS policy&lt;BR /&gt;flow_dos_ag_curr_sess_add_incr 12 0 info flow dos Incremented aggregate current session count on session create&lt;BR /&gt;flow_dos_cl_curr_sess_add_incr 12 0 info flow dos Incremented classified current session count on session create&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2021 19:54:40 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2021-02-25T19:54:40Z</dc:date>
    <item>
      <title>Why I see no logs for DoS policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387805#M90426</link>
      <description>&lt;P&gt;I am testing DoS policies and have alarm rate set as 1. I did not intend to be that low but I was not seeing logs under monitor for a server that is continuously used. There are&amp;nbsp; flood logs from Zone Protection and they use a different log forwarding profile for easy differentiation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;DOS policy&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30065i7D3F068E77486454/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Aggregate and classified profiles used in policy&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 725px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30066i66BBBA6734AD00AE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 709px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30067i83E80835590440F3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 16:19:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387805#M90426</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-02-25T16:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why I see no logs for DoS policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387848#M90434</link>
      <description>&lt;P&gt;Here is some information that may help..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Global Counters for DoS Activity Monitoring&lt;/STRONG&gt;&lt;BR /&gt;To supplement the Threat event logs for Zone and DoS protection, the following CLI commands can provide additional&lt;BR /&gt;information in the form of global counters and session count information to help identify DoS activity.&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt;show counter global name ?&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Lists all global counters&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt;show counter global filter aspect dos&amp;nbsp; &amp;nbsp;List all global counters with active DoS&amp;nbsp;aspect values&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Counter Aspects&lt;/STRONG&gt;&lt;BR /&gt;PAN-OS allows filtering of the Global Counters by category, aspect, and severity to make it easy to pull the relevant&lt;BR /&gt;counters for review. Counters of interest that are related to Zone and DoS protection include:&lt;BR /&gt;Category: Flow Aspect: dos&lt;BR /&gt;Category: Flow Aspect: parse&lt;BR /&gt;Category: Flow Aspect: ipfrag&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of CLI command to extract Flow counters with a DoS aspect:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt;show counter global filter category flow aspect dos&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:11:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387848#M90434</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-02-25T19:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why I see no logs for DoS policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387879#M90441</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp; I checked and as you can see below on setting the filter to that IP i can see Syn cookies are sent. But why does it not show in logs is my problem. I know its not much but its still higher than alarm rate of 1 and should show in threat logs as cookie sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter match destination X.X.X.X&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;show counter global filter delta yes packet-filter yes aspect dos&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 7.374 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;flow_dos_syncookie_cookie_sent 16 1 info flow dos TCP SYN cookies: cookies sent, aggregate profile/zone&lt;BR /&gt;flow_dos_syncookie_ack_rcv 25 1 info flow dos TCP SYN cookies: ACKs to cookies received, aggregate profile/zone&lt;BR /&gt;flow_dos_cl_syncookie_ack_rcv 4 0 info flow dos TCP SYN cookies: ACKs to cookies received, classified profile&lt;BR /&gt;flow_dos_rule_allow_under_rate 78 6 info flow dos Packets allowed: Rate within thresholds of DoS policy&lt;BR /&gt;flow_dos_rule_match 78 6 info flow dos Packets matched DoS policy&lt;BR /&gt;flow_dos_ag_curr_sess_add_incr 12 0 info flow dos Incremented aggregate current session count on session create&lt;BR /&gt;flow_dos_cl_curr_sess_add_incr 12 0 info flow dos Incremented classified current session count on session create&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/387879#M90441</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-02-25T19:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why I see no logs for DoS policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/401369#M91690</link>
      <description>&lt;P&gt;Both Zone Protection and DoS policies cannot have TCP-SYN enabled at the same time, Resolved while troubleshooting with support.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 18:14:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-i-see-no-logs-for-dos-policies/m-p/401369#M91690</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-04-22T18:14:26Z</dc:date>
    </item>
  </channel>
</rss>

