Panorama data detailed logs
hi TeamPlease tell how much time frame can detailed logs can retain e.g traffic on panorama before they start to purge to summary database?or if panorama data detailed logs work differently please tell.?
hi TeamPlease tell how much time frame can detailed logs can retain e.g traffic on panorama before they start to purge to summary database?or if panorama data detailed logs work differently please tell.?
Has anyone else noticed that the URL Cache is not cleared after 7 days (default setting) version 4.1.6. We have submitted several changes to Brightcloud and they updated the definitions 23 days ago. Even after the new definitions were installed the following day (4 updates since), after 22 days the URLs were still categorized wrong by the PAN. ...
Hello,I had set ssl-decryption on FW to connect GMail.The below screenshot shows.Probalbly, It is FW's response page.What is this?
Hi,I want to distribute our syslog-messages to different servers. Since we are using the Palo Alto system as Internet Security Gateway, a lot of traffic gets logged. But I only want to forward special services (systems more important than usual webtraffic) to our syslog servers. Is there a way to filter which targets/sources gets logged via syslog?
Watching the latest video from Palo Alto Networks found at:What's in the Box?: A Behind-the-scenes Look at the Next-Generation Firewallhttps://www.youtube.com/watch?v=qcPWMyne2a8one can see at frames close to the 00:30 mark:https://www.youtube.com/watch?v=qcPWMyne2a8&t=30sa code-snippet that says:"if self.platform in ['7000']:"is this a prev...
A discussion in a IRC-channel this evening was regarding the ongoing DDoS against wordpress installations all around the world and what to do in order to protect your webservers from the known bad ip addresses.Using ACLs in for example a modern Cisco router seems to only be able to handle something like 1-10k ace's depending on masks being used ...
Are there any instructions or can someone shed some light on doing only URL filtering on the PA and not using it as a firewall yet.
Hi There!I have a problem accessing Microsoft site for downloading hotfixes...The button "download" just disappearedIt should looks like this.... but .. I have A VERY SLOW CONNECTION and THIS:Any Ideas?Thank you!Kind regards,Alex
I know there is like brute-force category, where some may have it automatically block the IP for some duration.I was wondering if there is a way to block IP for x duration if they were doing like a scan against your system, trying multiple vulnerabilities, sometimes the same ones, sometimes moving down the list depending the type of scan.Like fo...
1)Under Alerts section when I want to get an alert on Unit42 tags on My Samples, does this look for unit 42 tags specific to my industry or all Unit 42 tags?2)Also, is there a way i can have different levels of private tags to prioritise my alertsfor e.g for adware i send an alert only to my L1 team but for cryptolocker i send it to themanagemen...
All,In our current URL filtering setup (WebWashers utilizing WCCP) we have rules setup that allow a particular AD group access to pandora which works fine. We're trying to port this rule over to our PAs but am running into some issues.In the Security Policy I have a rule setup that allows the pandora group to use flash,pandora, web browsing, and...
Hey guys...so I have a request - Users in my company who are not up to speed on corporate training will be added to the "corp\DelinquentUsers" AD group. I need to make sure that these guys are only allowed to go to 5 websites while they are part of this group.Currently HTTP access is anything unless its matched in our URL blocking profile (Gam...
Can the threats logs be sent to a 3rd party syslog server?
We have a PA5050 device with PremiumSupport expired on 2012-12-19T00:00:00. We could not open support case because of this. Our configuration include single PA5050 device with one SSD drive. on Jun 10 00:14:08 our device became unavailable and died (the day of PAN OS 7.0 announcement?!). We have detected that something happened to the SSD drive ...
Hello,My question is based the following document.How Application-Default in the Rulebase Changes the Way Traffic is MatchedThe case on above document is allowing rule.I wonder another case when there is a blocking rule with service any how traffics are matched.There are rules as below image.I have found some odd traffic logs out as below screen...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 2 |

