General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

Resolved! MineMeld - Unable to locate package minemeld

Hey, I just installed Ubuntu 16.04 to set up MineMeld according to these instructions:https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-Install-MineMeld-on-Ubuntu-Server-16-04/ta-p/253336 Once running sudo apt install -o Dpkg::Options::="--force-overwrite" -y minemeldI get the following Error: E: Unable to locate package minemeldWh...

husetech by L2 Linker
  • 4427 Views
  • 2 replies
  • 0 Likes

Free visualisation (NOC screenboards) for PANW firewall performance/monitoring using Elastic Stack

I was looking for ways to provide 'at-a-glance' visualisation of PANW firewall health, including traffic, threat, system & config logs. The stock capabilities, including ACC, are decent but somewhat lacking in providing NOC-style dashboards. Inspired by other visualisation solutions I've seen around, such as the Splunk App & Graylog dash...

Resolved! Application 'github-base' and SSH

Hi all, Can someone please explain why the "github-base" application depends on SSH? We are running into a number of problems with web sites that are hosted on Github. Users want to get to these sites for legitimate reasons. IT people have also wanted to download Github projects. I don't have a problem with approving github-base, but we h...

RSKadish by L2 Linker
  • 18122 Views
  • 7 replies
  • 0 Likes

Maximum VPN Tunnels on a PA-820

Hello,Does anyone know what the maximum VPN tunnels are on the new PA-820 firewalls? The current doc out there does not include the new 220, 800, 3200, or 5200 series firewalls. Thanks.

Resolved! Global Protect with Multiple Portals - Transparent Configuration

Have a client who is rolling out a global GP deployment and looking for redundancy. We have setup portals and gateways on all of their firewalls and everything is working great from being able to connet to the right gateway to being able to choose different gateways. We have now started discussing HA for the portal FQDN itself as this seems to ...

Error process CSV files published as Microsoft Articles

Hi, I'm using pluging "ms-article-miner" from Xavier Homs to miner ip Microsoft space. https://github.com/xhoms/minemeld-msarticle https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Miner-to-collect-Microsoft-Public-IP-space/td-p/186591 Firstly it was working but now it does not show anything. It shows in miner and processor but not...

Threat email alert throttling

We're setup to email threat alerts, and are getting an email for every alert generated.Is there a way to throuttle the emails? Particularly for a single threat that is blocked, we don't need 60 emails/min for all the blocks. It would suffice for the first 10 per 10 min interval. When you get the first 10 emails, you know someone is hammering you...

CHKlomp by L2 Linker
  • 3322 Views
  • 2 replies
  • 0 Likes

How to filter O365 API feed?

I would like to filter for indicators with the category "allow" or "optimize" only. How would you define the filter for that? I cannot find that much information regarding filtering using a processor. I hope my steps are correct? create a new prototype of the IPv4Generic processor create infilters for that infilters: - actions: - accept ...

Resolved! Office 365 MineMeld Miner Will Need Updating

Microsoft has announced a change to their Office 365 address and url documentation that I believe will need to be taken into account on the O365 miner in MM. https://myitforum.com/microsoft-phasing-out-office-365-urls-and-ip-address-ranges-resource-on-october-2-2018/ Basically, they are phasing out the old documentation page, which I believe...

Panorama Task Manager Is loading || unable to see any completed jobs history

Hi Team, We having Panorama which manages more then 30 devices, The problem I facing is when I check the Task manager on the left bottom it's loading continously and unable see any completed or ongoing processes of all devices even if I wait more then 30 minutes.But I can see those last jobs on managed devices coloum. I could not found any artic...

image.png

Resolved! Polling JSON Format for Okta

I am trying to create a prototype for a Miner that pulls IP's from a JSON formatted file. I have looked at the documentation for setting up a JSON miner (https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-extract-indicators-from-a-generic-API/ta-p/218757) and I am having little luck as the error messages in the logs are say...

doliver1 by L0 Member
  • 14868 Views
  • 7 replies
  • 0 Likes

Nonsense configuration changes from "preview changes"

Hello everybody, from time to time, whenever I commit small changes to my PAN firewalls, if I click on the "Preview changes" button I see (beside my changes) a list of items and configuration partials that are moved around, ie custom report configurations deleted from the top of the config and then added again in a lower portion of the config ...

grenzi by L3 Networker
  • 4228 Views
  • 2 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels