Is it possible to create the custom report each category in spyware?
cancel
Showing results for 
Search instead for 
Did you mean: 

Is it possible to create the custom report each category in spyware?

L4 Transporter

Hello

My customer would like to see only CnC threats after the filtering.

So I think to use the filtering for spyware category.

But there are only 'any' and 'unknown' in threat logs.

I want to use the each spyware category such as botnet , backdoor and etc.

How should I do?

Thanks,

KC Lee

1 ACCEPTED SOLUTION

Accepted Solutions

L6 Presenter

I don't think this is supported.There is no way to filter categories.

View solution in original post

4 REPLIES 4

L5 Sessionator

Hello Lee,

Palo Alto daily generate a report for spyware under 'Monitor->Reports->Threat Reports.

Is this what you are looking for?

Regards,

Hari Yadavalli

Hello cheon,

From the Threat database selected from the custom reports we can set the filters such that we are looking for type "Spyware" and filter all the spyware threat logs.

The allowed Threat types are flood, scan, spyware, virus, vulnerability.

So if we are looking for anything outside these then we have to go for predefined reports as pointed earlier by hyadavalli where we can find the botnet and other reports.

Thanks

L6 Presenter

I don't think this is supported.There is no way to filter categories.

View solution in original post

Thank you for the answser, hyadavalli , Phoenix and panos.

As panos mentioned, I think so too.

I can not filter each spyware category in threat logs or custom report.

But I have gotten some idea for filtering command and control, recently.

I read the spyware phone home detection value of threat id fields are between 10000 ~ 19999 in the integration syslog document.

So I will make the filtering as below in threat logs.

(threatid geq 10000) and (threatid leq 19999)

How do you think about it?

Do you have any idea better than it?

Thanks,

KC Lee

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!