Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

About Automation/API Discussions

Threads in this discussion area are now read-only. If you have a question about Automation/API products please visit our product discussions.

Discussions

Activeync, iislogs and user-id

I have been battling a problem for quite sometime. I think the end result is I somehow need to dig through the IISLogs for activesync information and pass it to the PA via their API. Unfortunately I have no clue how to get started on this.Story is as follows:Typical AD environment. Ipads and other non domain devices are coming inside our netw...

BobW by L4 Transporter
  • 5118 Views
  • 6 replies
  • 0 Likes

USER-ID API Ip Address not known at start

I have set up my freeradius system to pass XML updates to the user ID agent. however I have found that with my Juniper wireless system, at the point of the RADIUS "start" accounting message, it doesn't know the users IP address.My guess is that once the IP address is allocated it will sent an accounting update with the correct details, so I am h...

djr by L4 Transporter
  • 2802 Views
  • 0 replies
  • 0 Likes

User-ID XML API error 5-10054!

Hi, I am just starting to use the User-ID XML API to integrate with RADIUS and my attempts to update the 4.1.0-43 agent returns "XML api ssl 0 accept error: 5-10054!"Does anyone know what this error means and is there a list of error codes so I can look them up myself?ThanksDavid Rickard

djr by L4 Transporter
  • 5238 Views
  • 2 replies
  • 0 Likes

Resolved! ISSUES WITH CUSTOM VULNERABILITY

Hi All, We are making the creation of a "Custom Signature" to detect an XSS vulnerability identified in the player JWPLAYER The vulnerability occurs in / media / players / jwplayer / player.swf and HDSMediaProvider.swf. Model: PA-4050 Software Version: 4.0.11 For this we register accesses can be made to the player JWPLAYER with parameters in ...

noc_soc by L0 Member
  • 5643 Views
  • 2 replies
  • 0 Likes

Response Page - Available Tags

Hi all,Would anyone have the full range of device vaiables available to the response pages? I have response pages that I'm trying to emulate in PAN from our outgoing URL filtering solution and I need things like the virus name (not just the filename), virus URL, that sort of thing and I need a more complete reference than the source for the def...

Limits on a pan::xapi connection?

I'm working on a script to check several configuration options on a PANOS box. It seems that after 10 actions or so, the api connection fails. Is there a limit within the API that says a single instantiated api connection can only complete x amount of actions before a new connection must be established? My code is fairly simple, I call the ap...

sheist by L1 Bithead
  • 4213 Views
  • 3 replies
  • 0 Likes

Limits on a pan::xapi connection?

I'm working on a script to check several configuration options on a PANOS box. It seems that after 10 actions or so, the api connection fails. Is there a limit within the API that says a single instantiated api connection can only complete x amount of actions before a new connection must be established? My code is fairly simple, I call the ap...

UhMayYeah by L5 Sessionator
  • 2346 Views
  • 1 replies
  • 0 Likes

Need a little help with PAN::API on Linux

I just installed the User-ID API PAN::API system on my Linux server to pass wireless syslog information to a Palo Alto User-ID Agent. The problem is the User-ID Agent does see the connection from Linux, but does not post the passed user logon data. The test Perl script is very small;#!/usr/bin/perluse strict;use warnings;use diagnostics;use PA...

EdCricket by Not applicable
  • 2370 Views
  • 1 replies
  • 0 Likes

Getting the PAN XML API to work using rsyslog instead of Kiwi...

Hey guys,Has anyone ever got the PAN ID XML API to work with rsyslog?I am trying to parse my VPN Concentrator Logs (which are sent to my rsyslog server) and see if I can run it through the API module which will then send the data over to the PAN UserID Agent.I am writing a simple perl script to scrape sample VPN log data first and then port that...

ikinnexi by Not applicable
  • 3011 Views
  • 1 replies
  • 0 Likes

Query User-id database from XML API

I see that you can query the user-id database from the CLI with the "show user" command but can do you do the same via the XML API?I am unable to find a user related option in the API browser.

mgoodman by L0 Member
  • 3376 Views
  • 1 replies
  • 0 Likes

Need Assistance with Custom Signature for Shamoon

We are alerting on Shamoon on our IDS systems, but we want to write a custom signature for the PANs. Shamoon has two signatures for snort:alert tcp $HOME_NET any -> any $HTTP_PORTS (msg:"MALWARE-CNC Win.Trojan.DistTrack command and control traffic"; flow:to_server,established; content:"/ajax_modal/modal/data.asp"; nocase; http_uri; content:"...

dgilliam by L0 Member
  • 3500 Views
  • 1 replies
  • 0 Likes

Resolved! Having trouble with panxapi

,hello,I'm experiencing an issue with panxapi where it returns a success code (19), but the result is actually not being received. I'm using the -x and -g options to try and pull back the pre-rulebase on my panorama for a specific device group.The xpath works in the API browser, but when I apply the same to the panxapi command I get nothing bac...

sheist by L1 Bithead
  • 3819 Views
  • 1 replies
  • 0 Likes
  • 1031 Posts
  • 68 Subscriptions