Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Discussions
Check out LIVEcommunity discussions to find answers, get support, and share knowledge related to Palo Alto Networks tools and products.

Browse the Community

General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

24432 Posts

Custom Signatures

The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.

176 Posts

VirusTotal

Have you encountered a false positive verdict for Palo Alto Networks (Known Signatures) on VirusTotal? Use this forum to submit a verdict change request. Change requests should include the File Hash, Link to VirusTotal report, current VirusTotal verdict, and description.

805 Posts

Network Security

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to all things Network Security.

4975 Posts

Cloud Delivered Security Services

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Palo Alto Networks’ Cloud Delivered Security Services.

657 Posts

Secure Access Service Edge

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Prisma Access and Prisma SD-WAN.

579 Posts

Security Operations

Post questions, provide answers, share best practices, and connect with peers and experts in this area dedicated to Cortex XDR, XSOAR, and Xpanse discussions.

4620 Posts

Activity in Discussions

TrendMicro Apex One Alert mapping into XSIAM

Hi All Has anyone done this to date and willing to share their Correlation XQL logic used to map alerts from Apex One into XSIAM? I have done this for a few others already like Crowdstrike, MS Graph API etc but having issues with time to navigate through all the raw log data to determine the required fields to validate and alert on what is requi...

PA_nts by L4 Transporter
  • 36 Views
  • 0 replies
  • 0 Likes

Cortex XDR JDP method instrumentation causing severe Java runtime slowness (agent 9.2.0.120) — follow-up to solved cyjagent crash thread

This is a follow-up to a previously solved thread: Cortex XDR cyjagent.dll injection causes JVM startup crash, where @susekar confirmed the known JDP/JVM conflict (CPATR-38467 / CPATR-18158). Thanks for that confirmation. Since the solution there is already accepted, raising this as a separate topic: we've now observed a second symptom from the ...

XSIAM logs from Palo Alto Firewall using syslog

https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrations/next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector Why does the official guide only highlight Custom Formats for Traffic, Threat, URL, and File data logs? What about other NG...

Firewall Bios update after activating a new GlobalProtect version

Ran into an oddity today, and I'm not sure if I fully believe support. I upgraded our firewall last week to 12.1.7-h3, all went fine system is running normally. Today I decided to start testing the new version of GlobalProtect (6.3.3-h11). When activating it, it asked if I wanted to do a system health report. Seemed kind of weird, would expe...

PatWruk by L1 Bithead
  • 80 Views
  • 0 replies
  • 0 Likes

Rethinking Threat ID: 31671 (SCADA ICCP Unauthorized COTP Connection) — Is This Really Malicious?

When reviewing security alerts, context is everything. Take Threat ID: 31671 ("SCADA ICCP Unauthorized COTP Connection Established"), for instance. The current description simply states: "This alert indicates that an ICCP client has successfully connected using OSI Connection Oriented Transport Protocol." While seeing a successful connection pop...

XSIAM documentation in PDF form

Is there any spot where I can just download the documentation for the "admin" guide or the XQL reference that isn't just printing the web page to a PDF? Trying to use the new search function which forces the AI agent is not a pleasant experience for me.

Unable to Connect to Global Protect 6.3.4 iPhone and iPads

Hello everyone, We're experiencing an issue with GlobalProtect on managed iPads and iPhones version 6.3.4-23. I'm trying to determine whether anyone else has run into this recently. Environment GlobalProtect VPN deployed via Microsoft Intune iPadOS devices Authentication through PingID (SAML) VPN type: Palo Alto Networks GlobalProtect Authent...

mtruong_0-1787151999535.png
mtruong_1-1787152104165.png
mtruong by L0 Member
  • 57 Views
  • 0 replies
  • 0 Likes

Real-Time BIOC Detection and Playbook Execution for SSH/RDP Sessions

Hello, I am working on a Playbook to detect RDP/SSH communications between servers and automatically terminate the corresponding process when such communication is detected. As a preliminary test, I have configured a small-scale test to verify that the process can be automatically terminated. My current configuration is as follows. 1. XDR Enviro...

.522643 by L1 Bithead
  • 72 Views
  • 1 replies
  • 0 Likes

PA-5200 Series Enviroment

Hi I have a question regarding the output of the 'show system environmentals' command on the PA-5200 Series. Could someone explain the difference between 'NP / NP Core' and 'CP / CP Core' in the output results? In my opinion, NP and CP are likely hardware accelerators, such as a Network Processor and a Content Processor, respectively. However,...

Always on and user MFA

Trying to configure Global Protect on new firewalls and update the MFA Current configuration:Clients configured w/always connected. Portal is configured w/pre-login device certificates from internal PKI. GW is configured w/LDAP and RADUIS. When a user tunnel is established, user must push yubikey to complete the config. New Configuration: We...

C.Meisch by L1 Bithead
  • 56 Views
  • 0 replies
  • 0 Likes

ZTNA Connector — Tunnel remains Inactive despite active Control Plane (NFR tenant)

Hello Evryone, I'm tring to deploy a ztna connector on my home lab to prepare different use case for customer demo and i still have the same issue. Environment: Tenant type: NFR ZTNA Connector deployed on-prem via KVM (Proxmox VE), two-arm deployment Connector image: 200v-6.2.9-ztna-connector-b3-kvm.qcow2 (and try with 6.2.5 same issue) Port 1...

Resolved! SBAC for DLP add-on

Hello All, Would SBAC also works for DLP (add-on) module events? We wou ld enable SBAC for those Endpoints with DLP enable by department. Then allow each department head as the Data Security Reviewer to view their own DLP events. Possible to do so? Thanks, SDH

Move my Panorama vm from VSphere to Hyper-V

We are changing our hypervisor platform from VMware to Hyper-V. Our normal migrate process (Shutdown, Backup with Veeam, Live Migrate to Hyper-V) failed with #Panorama, perhaps not unexpectedly How can I migrate my current setup?

J.Dore by L0 Member
  • 90 Views
  • 1 replies
  • 0 Likes