Threat monitoring ( empty reports )

Reply
Highlighted
Not applicable

Threat monitoring ( empty reports )

Hello All,


Currently we have a daily Threat monitoring report sent out.

If the report is empty (which it often is) it somewhat defeats the object as someone has to open it and read it only to find no issue.

Is there a way to run it more on an exception basis i.e. only send an email if a threat has been detected ?

I’ve read the security profiles section of the manual but cant see anything relevant.


Best regards,


David Sanchez


L5 Sessionator

Re: Threat monitoring ( empty reports )

1> Currently PAN_OS firewalls do not have a provision to send reports based on a trigger condition such as Threat detection.

You may configure email alerts using Email server profiles which would send you an email when a Threat log is generated.

You may run reports manually when these alerts are received.

2>Setps to configure :

How to receive Email threat notification?

3>You may contact your SE to discuss the options for filing a Feature request if this feature is important to you.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!