Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Anyone using save/load filter optins under Monitor tab?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Anyone using save/load filter optins under Monitor tab?

Cyber Elite
Cyber Elite

Out of curiosity is anyone using Save Filter and Load Filter options under Monitor tab and find them user friendly?

I have mentioned to Palo representatives few times that filter field should have droppdown history like browser address bars have but they always suggest to go with save/load option that i really dislike 🙂

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
3 REPLIES 3

Cyber Elite
Cyber Elite

The only time I use them is usually really long queries that generally and even then they have to include specific threat identification ids before I use them. Usually I just forget that they are even there and move on. I see PAs point with not wanting a drop down history though; I run a lot of query's that I will likely never need again and wouldn't want them constantly popping up. 

Yeah issue is that usually you are working on something and have filter almost set.

And then colleque comes and asks "hey please check this for me real quick...".

Notepad helps out in those cases but there must be easier way.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L7 Applicator

I only have one filter saved, but it's one I use all the time while in the Unified Log Viewer.  It's:

 

    (action neq allow) and (action neq alert) and (app neq teredo) and (app neq quic) and (addr in x.x.x.x)

 

This one is great because it will show you if something's being blocked for a specific IP address, inbound or outbound, URL or Threat, or File Type, etc.  I put the teredo/quic apps in there because they're blocked & logged right now and I don't want to see those in this specific query.  I also use the more generic "addr in x.x.x.x" instead of specifying source or destination address... because I want to see hits where x.x.x.x was the source (usually outbound connections, URLs, etc.) but also want x.x.x.x as the destination too (for blocked files, threats, etc.)  

  • 2155 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!