<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filtering, Notification, Approval processing capability in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137015#M97688</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In some use-cases, we may want to have the following features:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Filtering - Maybe a list of search strings that if matched are excluded from the output
&lt;UL&gt;
&lt;LI&gt;Use-Case: URL lists for O365 are very messy, and sometimes we don't trust all the output given by MS. &amp;nbsp;We may want to filter certain URLs from getting added to the output&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Notification - Knowledge of new additions/removals to an output via email, syslog, HTTP call, or whatever other notification framework fits best with the project (I do see there are logs in the Log tab, but I am not sure exactly the meaning, and/or if anything can be done with these logs)
&lt;UL&gt;
&lt;LI&gt;Use-Case: Some lists may need to be monitored closely, particularly lists that do not change often or have significant impact in the environment. &amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Approval - Approve changes before they are added to an output
&lt;UL&gt;
&lt;LI&gt;Use-Case: Similarly with O365, we may want to approve the changes rather than trust them by default. &amp;nbsp;Some vetting process may be done by the admin, and they would decide to add something to the filter or approve the changes&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would this be some kind of processor node that handles these?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there something I am missing that is already doing this or maybe doing it in a different way than I have framed it up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;~ Andrew&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 17:01:51 GMT</pubDate>
    <dc:creator>andrew.stanton</dc:creator>
    <dc:date>2017-01-11T17:01:51Z</dc:date>
    <item>
      <title>Filtering, Notification, Approval processing capability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137015#M97688</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In some use-cases, we may want to have the following features:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Filtering - Maybe a list of search strings that if matched are excluded from the output
&lt;UL&gt;
&lt;LI&gt;Use-Case: URL lists for O365 are very messy, and sometimes we don't trust all the output given by MS. &amp;nbsp;We may want to filter certain URLs from getting added to the output&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Notification - Knowledge of new additions/removals to an output via email, syslog, HTTP call, or whatever other notification framework fits best with the project (I do see there are logs in the Log tab, but I am not sure exactly the meaning, and/or if anything can be done with these logs)
&lt;UL&gt;
&lt;LI&gt;Use-Case: Some lists may need to be monitored closely, particularly lists that do not change often or have significant impact in the environment. &amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Approval - Approve changes before they are added to an output
&lt;UL&gt;
&lt;LI&gt;Use-Case: Similarly with O365, we may want to approve the changes rather than trust them by default. &amp;nbsp;Some vetting process may be done by the admin, and they would decide to add something to the filter or approve the changes&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would this be some kind of processor node that handles these?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there something I am missing that is already doing this or maybe doing it in a different way than I have framed it up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;~ Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 17:01:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137015#M97688</guid>
      <dc:creator>andrew.stanton</dc:creator>
      <dc:date>2017-01-11T17:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering, Notification, Approval processing capability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137515#M97689</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33044"&gt;@andrew.stanton&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;all your points are extremely good. A manual approval workflow and notifications is something we are planning to add and we have started thinking about it. As a starting point how would you like to handle notifications ? email ? Slack ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About filtering, you can use whitelists or infilters feature of nodes to filter out specific URLs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;luigi&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jan 2017 06:07:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137515#M97689</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2017-01-14T06:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering, Notification, Approval processing capability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137976#M97690</link>
      <description>&lt;P&gt;standard internal corporate SMTP would likely be a good starting point&lt;/P&gt;
&lt;P&gt;maybe syslog as well&lt;/P&gt;
&lt;P&gt;i would adhere to similar methodologies as the firewall software for continuity, but your development resources are probably different than for PAN-OS.&amp;nbsp;I don't know much about RSS, but would that be a good idea? HTTP callout? SNMP trap would probably be unnecessary and never adopted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have an example on the filtering with whitelists or infilters feature or point me to another document?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;~ Andrew&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 22:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/137976#M97690</guid>
      <dc:creator>andrew.stanton</dc:creator>
      <dc:date>2017-01-17T22:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering, Notification, Approval processing capability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/198916#M97691</link>
      <description>&lt;P&gt;I echo the suggestions below. If there was also a robust API, this might be able to be scripted external to MM, but even just a syslog would be useful to create at least the notification.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 00:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/filtering-notification-approval-processing-capability/m-p/198916#M97691</guid>
      <dc:creator>jgeyer</dc:creator>
      <dc:date>2018-02-06T00:37:03Z</dc:date>
    </item>
  </channel>
</rss>

