General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4464 Views
  • 0 replies
  • 0 Likes

Resolved! How to allow Solarwinds IPAM port scan?

Hello,I have solarwinds with IP address manager and when the IPAM does a subnet scan the PAN alerts this as a threat and blocks the source ip address, which is the Solarwinds server, then I get alerts that everything on that subnet is down. How would I make a rule so this scan does not go down as a threat. Thank you in advance.

H in IP address

Hello, through panorama I am looking at my threat logs and noticed under the attacker column there is an H in front of my IP Address. What does the H mean ?

Wildcards in Log Filtering

Hi All,I'm trying to figure if if I can use wild cards when constructing a filter in Monitor -> URL Filtering. I want to get all records that contain '@*.domain.com'.My current filter is ( url contains '@staff.domain.com' ) what I want is ( url contains '@*domain.com' )Can this be done?thanksLeigh

LeighV by L1 Bithead
  • 14520 Views
  • 6 replies
  • 0 Likes

Disk space alert

Hi everybodyIt is posible generate alerts or system logs when the partition sda2 or sda3 is soon to fill?Thank you for your help.Best regasds.

Claudia by L0 Member
  • 6939 Views
  • 4 replies
  • 0 Likes

Panorama data detailed logs

hi TeamPlease tell how much time frame can detailed logs can retain e.g traffic on panorama before they start to purge to summary database?or if panorama data detailed logs work differently please tell.?

URL Cache not clearing after 7 days

Has anyone else noticed that the URL Cache is not cleared after 7 days (default setting) version 4.1.6. We have submitted several changes to Brightcloud and they updated the definitions 23 days ago. Even after the new definitions were installed the following day (4 updates since), after 22 days the URLs were still categorized wrong by the PAN. ...

craymond by L4 Transporter
  • 3496 Views
  • 1 replies
  • 0 Likes

Syslog-Messages only for some security rules?

Hi,I want to distribute our syslog-messages to different servers. Since we are using the Palo Alto system as Internet Security Gateway, a lot of traffic gets logged. But I only want to forward special services (systems more important than usual webtraffic) to our syslog servers. Is there a way to filter which targets/sources gets logged via syslog?

PA-7000 series is the next hardware in pipe?

Watching the latest video from Palo Alto Networks found at:What's in the Box?: A Behind-the-scenes Look at the Next-Generation Firewallhttps://www.youtube.com/watch?v=qcPWMyne2a8one can see at frames close to the 00:30 mark:https://www.youtube.com/watch?v=qcPWMyne2a8&t=30sa code-snippet that says:"if self.platform in ['7000']:"is this a prev...

mikand by L6 Presenter
  • 8049 Views
  • 13 replies
  • 1 Likes

Resolved! How to efficiently block a large number of ip-addresses?

A discussion in a IRC-channel this evening was regarding the ongoing DDoS against wordpress installations all around the world and what to do in order to protect your webservers from the known bad ip addresses.Using ACLs in for example a modern Cisco router seems to only be able to handle something like 1-10k ace's depending on masks being used ...

mikand by L6 Presenter
  • 19720 Views
  • 15 replies
  • 0 Likes

Microsoft sites: downloading problem

Hi There!I have a problem accessing Microsoft site for downloading hotfixes...The button "download" just disappearedIt should looks like this.... but .. I have A VERY SLOW CONNECTION and THIS:Any Ideas?Thank you!Kind regards,Alex

Oleksandr by L3 Networker
  • 6989 Views
  • 5 replies
  • 0 Likes

Automate Block IP

I know there is like brute-force category, where some may have it automatically block the IP for some duration.I was wondering if there is a way to block IP for x duration if they were doing like a scan against your system, trying multiple vulnerabilities, sometimes the same ones, sometimes moving down the list depending the type of scan.Like fo...

googol by L3 Networker
  • 5067 Views
  • 3 replies
  • 1 Likes

Autofocus Alert Query

1)Under Alerts section when I want to get an alert on Unit42 tags on My Samples, does this look for unit 42 tags specific to my industry or all Unit 42 tags?2)Also, is there a way i can have different levels of private tags to prioritise my alertsfor e.g for adware i send an alert only to my L1 team but for cryptolocker i send it to themanagemen...

bmurali by L1 Bithead
  • 2615 Views
  • 1 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels