How Can I create custom application?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How Can I create custom application?

L3 Networker

Hello Family~

I would like to create custom application,,

but It is hard to do

anyway

recently I red custom application document

about uploading.com

\.   <- why include \ character?

I tried to what could have known where document;;

help me please,,

1 accepted solution

Accepted Solutions

L5 Sessionator

I think you are referring to this doc https://live.paloaltonetworks.com/docs/DOC-2015.

\. is a regex pattern which is being used https://live.paloaltonetworks.com/docs/DOC-1499

For regex pattern to work we need atleast 7 characters with no interpreted characters.

In this case you can very well use uploading.com without any \. What \. does is escape the period.

Following discussion talks more about regex pattern matches

https://live.paloaltonetworks.com/message/28486

View solution in original post

4 REPLIES 4

L5 Sessionator

I think you are referring to this doc https://live.paloaltonetworks.com/docs/DOC-2015.

\. is a regex pattern which is being used https://live.paloaltonetworks.com/docs/DOC-1499

For regex pattern to work we need atleast 7 characters with no interpreted characters.

In this case you can very well use uploading.com without any \. What \. does is escape the period.

Following discussion talks more about regex pattern matches

https://live.paloaltonetworks.com/message/28486

L4 Transporter

Tiger,

      The \ 'escapes' the following character (in this case a '.') so that the regex engine treats it as a normal character instead of the regex special character '.' Without escaping first, the regex engine treats that period as a sort of wildcard character that will match anything but a newline. Escaping it causes the engine to treat is as an actual period to be matched against. Hopefully this helps.

Hi,

try watch this video - https://live.paloaltonetworks.com/videos/1317 Maybe this will help Smiley Wink

L4 Transporter

Creating a custom app is actually fairly simple to do, it is just a little hard to understand Smiley Wink. There is a simple way, and a more complex way. The complex way is a much more useful tool. The simple way is to create a custom app by clicking add in application objects, give it a name and then check the box marked Continue scanning for other Applications. Then click on policies tab and select application override. Click add and name it, give it a source and destination, and the port(s) that it uses, select the custom application that you created and presto you have that unknown-tcp or unknown-upd traffic show in the logs as your custom app.

The more complex method entails actually packet capturing the traffic and creating a signature based on that traffic. The document that sraghunandan, posted:

https://live.paloaltonetworks.com/docs/DOC-2015 does a far better job of explaining that I could. For non-http traffic, I have used unknown-req-tcp-payload, and hex string matches, with defined ports. Just remember the \x at the beginning and the end!

The inherent vice of capitalism is the unequal sharing of blessings; the inherent virtue of socialism is the equal sharing of miseries.
  • 1 accepted solution
  • 3963 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!