Endpoint (Traps) Discussions
cancel
Showing results for 
Search instead for 
Did you mean: 
Endpoint (Traps) Discussions
About Endpoint (Traps) Discussions

Welcome to the Endpoint discussion forum! We encourage you to ask questions, propose solutions, and collaborate on ideas to better secure your endpoints with Traps.

Discussions

Syslog user-id - Regex ISE ranges

Hi


I have successfully created a syslog regex filter to receive incoming Cisco ISE authentications.  However, I want to filter some log entries based on only receiving from a particular IP address range and exclude some logs with certain characters in

...

Resolved! Block-continue feature

Hi,

 

so i was wondering if there is a rule/condition, that lets the user decide, wether to start an application or not (like a block-continue action on a PA-Firewall).

When i looked through the Exploit and Malware Tabs, i only found the option for eith

...

iweltag by L2 Linker
  • 1513 Views
  • 1 replies
  • 0 Likes

Alerting from Traps Cloud

Am I missing something or is this function not there?  It was there in the On-Prem version but in the cloud version I don't see anyway to setup alerts for things.  Definitely something that is needed quickly.

False Positive Removal Request

Hello,

Trap has been alerting and blocking this binary. It's a false positive.

https://www.virustotal.com/#/file/07c8d8afa8e90569ba9969d1c243f5fc05e3dc744406f83c2af62aa949cbb32c/detection

Could you please help remove this FP and instruct how to allow th

...

ndlan2k by L0 Member
  • 984 Views
  • 1 replies
  • 0 Likes

Traps Watchdog Service

Traps Watchdog Service stops, I cam to realize from the Event Viewer on different endpoints that the service Traps Watchdog stops after few seconds and up to a minute from starting, wether it was started due to system boot or started manually, this h

...

Resolved! Agent upgrade status

Hi!

I`m running ESM 4-1-3 and are currently upgrading my clients.

Where can I find more information about the status of my Action.

It currently says "Applied on: 81; Delivered: 2; Failed: 7"

The 81 I get, but what does Delivered 2 mean and where do I fin

...

trondk by L1 Bithead
  • 2224 Views
  • 3 replies
  • 0 Likes

Resolved! ESM (Server Side) Quarantine Size

Been running TRAPS for about 3-4 months now.  Recently got a notification that the ESM server (Windows OS) was getting low on disk space, started doing some investigation on it and noticed that the Quarantine folder located at C:\Program Files\Palo A

...