<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Activity (ACC) and Monitor-LOGS-threats are empty in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-activity-acc-and-monitor-logs-threats-are-empty/m-p/425146#M94327</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172299"&gt;@Ots-network&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you tried actually restarting the firewall and not just the mgmt server? Are you actually sure that no changes have been made and someone maybe didn't accidentally remove the security group/profile from your policies?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first thing I would do is verify through my traffic logs that traffic is hitting rules that actually have a security group/profiles assigned to it so that threat logs would actually be generated. Then I would just generate something stupid that I know should be getting logged as a threat, such as a directory traversal attempt or a simple unauthorized brute force attach on a login page.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Aug 2021 15:51:18 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-08-06T15:51:18Z</dc:date>
    <item>
      <title>Threat Activity (ACC) and Monitor-LOGS-threats are empty</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-activity-acc-and-monitor-logs-threats-are-empty/m-p/425054#M94320</link>
      <description>&lt;P&gt;As the title suggest i have on my fw (pan os 10.0.4)&amp;nbsp;Threat Activity (ACC) and Monitor-LOGS-threats totally empty.&lt;BR /&gt;Since few weeks ago no problem and all the other logs work fine.&lt;/P&gt;&lt;P&gt;And no changes have been made.&lt;BR /&gt;Any ideas?&lt;BR /&gt;&lt;BR /&gt;already restart mgmt service withuot success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 09:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-activity-acc-and-monitor-logs-threats-are-empty/m-p/425054#M94320</guid>
      <dc:creator>Ots-network</dc:creator>
      <dc:date>2021-08-06T09:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Activity (ACC) and Monitor-LOGS-threats are empty</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-activity-acc-and-monitor-logs-threats-are-empty/m-p/425146#M94327</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172299"&gt;@Ots-network&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you tried actually restarting the firewall and not just the mgmt server? Are you actually sure that no changes have been made and someone maybe didn't accidentally remove the security group/profile from your policies?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first thing I would do is verify through my traffic logs that traffic is hitting rules that actually have a security group/profiles assigned to it so that threat logs would actually be generated. Then I would just generate something stupid that I know should be getting logged as a threat, such as a directory traversal attempt or a simple unauthorized brute force attach on a login page.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 15:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-activity-acc-and-monitor-logs-threats-are-empty/m-p/425146#M94327</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-08-06T15:51:18Z</dc:date>
    </item>
  </channel>
</rss>

