Resolved! URL logs without URL Filtering license
Seems we have no url filtering license and we see no url logs under monitor.is this by design? only url logs i see is for custom block list?
Seems we have no url filtering license and we see no url logs under monitor.is this by design? only url logs i see is for custom block list?
Hello Community! I would like to know if we can use Palo Alto on our own VMs that we have deployed on Azure instead of deploying the firewall software through Marketplace (maybe get an image file or something that we can directly deploy on an Azure VM)?
We will soon be switching ISPs and will need to change the IP address of our "untrusted" external interface. This is the same interface/IP address that is associated with the GlobalProtect gateway and portal. Are there any special considerations with this change we should be aware of, or is it a simple matter of changing the IP and committing ...
This is often talked about from bot cisco and palo (when you use a pbr in aci to route some ports to the firewall)Is there anyone here acctuly using it?
While looking through logs to see why occionally a user gets reported as [email protected] instead of domain\user, we noticed the logs were filled with [email protected] as well. Is this expected?
I am trying to extract a list of IoC's from MM to pull into a SIEM via CSV lookup. When I connect to MineMeld using this syntax:- https://minemeld/feeds/Bad_IPv4?tr=1&v=csv&f=indicator&f=confidence&f=sources I get a list of indicators, but with no confidence\sources data (see output.png). I can check the same output node ...
Hello there!I have a question regarding the encryption of a certificate. Right now I am using a certificate issued by a Class 2 Certification Authority that is using SHA-1 encryption, but this is not satisfactory. How can I update the encryption type so the certificate uses SHA256 encryption?Thanks and regards
We have an interesting VPN request that's I have not seen yet. User logs into Global Protect from home and RDP's to desktop on campus. The user then tries to open a Global Protect connection from that campus workstation to get access to another restricted host on campus. The issue we have is when the user tries to connect on the second workstati...
So we recently started having trouble with our Palo's saying that the FQDN refresh job finished sucessfully but the items still TTL out and die. While waiting for support to look into it it occurs to me that I might beable to feed Minemeld a list of URL's and have it do the resolution and pump the results back to PAN. Anyone have any experience ...
good day,i know that answer might be simple but cannot find correct approach.I have an application which identified as unknown-TCP and i have created pattern for it with few conditions.now I have discovered that some devices behave different way and my pattern order not match, so I think to identify app based on first string in ASCII format.for ...
Dear experts, I am moving from PA3050 to PA3220. I did export the current configurations from the old PA3050 and imported to the new PA3220, i committed successfully, but when i migrate cables from old device to the new one i get random issues! like some zones are not reachable, like i have ping to internet and telnet and traceroute but i can't ...
各位朋友,现在有这么一个网络环境,公司网络出口部署PA3260,运营商原来分配的公网IP是IPv4地址,但现在运营商分配的是IPv6的地址,想请教各位有没有什么方法可以在内网(内网为IPv4的环境,公司有对外提供服务的服务器)变动不大的情况下出口IP顺利替换成IPv6的地址,之前本来想做一个NAT转换的,但是好像只能做NAT64,不知道新版本PA是否能做NAT46,或者有没有其他更好的法子,请各位朋友不吝赐教,谢谢!
Hi Team, I have a customer who use autofocus with minemeld and receive IoC feed to splunk through minemeld. I have a question about number of Daily IoC update. To our presentation, Daily update is over 230K from wildfire which one of threat feed in Autofocus but, I set minemeld as below picture(most of prototype I set) and I'm receiving IoC ...
Is it possible to chain a syslog input\miner to a DAG output? Scenario is I'd like to forward critical Threats to MineMeld to block the source address permanently (or at least longer than the max 3,600 seconds available as a block-ip IPS action) by bouncing back a DAG update (or failing that by adding to an EDL source etc). I have a way of d...
Ran through Install: $ sudo yum install -y wget git gcc python-devel libffi-devel openssl-devel $ wget https://bootstrap.pypa.io/get-pip.py $ sudo -H python get-pip.py $ sudo -H pip install ansible $ git clone https://github.com/PaloAltoNetworks/minemeld-ansible.git $ cd minemeld-ansible $ ansible-playbook -K -i 127.0.0.1, local.yml $ usermod -a...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 2 |

