General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Update 0.9.46 Broken (at least for me)

Hey all,

 

So my Minemeld appliance updated to 0.9.46 at some point which broke the system. I was able to temporarily fix the issue by just changing the symlink in /opt/minemeld/engine from 0.9.46 to 0.9.44. Obviously, this is not ideal.

 

When I loo

...

How to report false positive if I'm not a customer

Hello there, 

I represent Kromtech company(https://kromtech.com) which produces MacKeeper app (https://mackeeper.com). 

We have report from our partners that your WildFire service marks our products as Malware.

We would like to report false positive but

...

Screen Shot 2018-05-18 at 10.41.48 AM.png
ze0adik by L1 Bithead
  • 2434 Views
  • 1 replies
  • 0 Likes

Resolved! VM50 on Server 2016 HypperV

Does anyone know if the VM50 is supported on Windows Server 2016 Hyper-V?   I have downloaded the PANOS 8.0  Vhdx file and installed it based on the Server 2012  R2  Guidelines,  but every time I try to start the VM, I receive a message the virtual m

...

User-ID/Facebook allow group

Hello, 

 

I am having trouble with this configuration. 

 

In a Windows domain environment. 

 

I installed User-ID on server and confirmed User-ID is running and IP/user mapping is all listed in the monitoring log. 

 

User-ID agent is connected in the firewal

...

MineMeld Splunk App

Hi Guys,

 

I'm new to this community. At the moment, we are actively exploring MineMeld in our environment and would like to know if there is any connectors available for Splunk to consume intel collected by MineMeld .

Please advise.

Thank you.

Is my upgrade the cause of a vlan not working

After I upgraded my palo alto fro 7.1.15 to 7.1.16 I had a report that a certain vlan can not longer access the internet.  I have a back up of the config before the upgrade and one after the upgrade and so far I don't see any change in virtual router

...

jdprovine by L4 Transporter
  • 3429 Views
  • 9 replies
  • 0 Likes

Arp getting time out after 30 min on sub interface

We are facing some starnge issue .

We are having an ISP which is connected to sub interface.

We are trying to repalce it with new one. Same Subnet /29 but different IP. NAT rules also same because same subnet.

The issue we are facing is when new ISP con

...

Static Routes

We have a Cisco ASA that has tunnels to our branch offices.  An Example is 192.168.9.0/24.  The local network is 192.168.10.0/24.  The lan port of the ASA is 192.168.10.10.  The lan port of the Palo Alto is 192.168.10.1.  When I change the gateway to

...

Resolved! Risky ports

What are the risky ports we should not allow from user zone (internal network) to external network (internet / external network)? Like we don't allow 21/23 etc, please suggest other ports too.....

SumitB by L1 Bithead
  • 2522 Views
  • 3 replies
  • 0 Likes

Resolved! excluding threats from TAP allerting?

We have a TAP interface listening to a number of vlans (internal and external)

 

We get a lot of noise in our allerts from threats we would prefer not to get alerted on.

 

For example, presently "SipVicious"  scans are occuring all the time to what are a

...

MineMeld and ELK

Hi all,

 

I'm having some trouble parsing MineMeld events into Logstash, and then into ELasticSearch. Does anyone have any resources available for this kind of set up?

tom.dell by L0 Member
  • 3773 Views
  • 2 replies
  • 0 Likes

Bad Gateway Error - Minemeld Not Running

Hi All,

 

My Minemeld instance seemed to randomly break and I'm not sure why. When I try to login I get a bad gateway error and the EDL URL's give the same message. Here are some log snippets:

 

minemeld-engine.log:

 

2018-05-11T06:25:45 (4222)base.s

...

  • 24027 Posts
  • 102 Subscriptions
Top Liked Authors
Labels