- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-08-2017 06:43 AM
Palo Alto is currently logging URLs which includes a path such as webserver.com/code.exe?id=4 but Palo is capable of logging a message that would display just the code.exe filename as well as a content type such as application/x-octet-stream or ms-executable. I would like to have these FILE events. Does anyone have insight into this for a palo beginner? Any and all help is appreciated!
Fields Required:
- Filename
- Content Type
- File Size
- Any reputation scoring
06-08-2017 06:55 AM
Hi Jerm,
Yes you can do this with a file blocking profile.
First you will need to create a file blocking profile which can be done in the Objects tab then select file blocking on the left hand side menu.
Click add at the bottom to create a new profile then add in a rule to have the action 'alert' on all applications, file types etc.
Give the profile a name and click ok.
Go to your security policies under the policies tab and select the policy in which your traffic is hitting. In the actions tab of the selected policy, you can choose your new file blocking profile from the drop down if you select profiles.
Click commit in the top right hand corner to push the changes down to the data plane and make them active.
Let me know if this helps,
Ben
06-08-2017 06:55 AM
Hi Jerm,
Yes you can do this with a file blocking profile.
First you will need to create a file blocking profile which can be done in the Objects tab then select file blocking on the left hand side menu.
Click add at the bottom to create a new profile then add in a rule to have the action 'alert' on all applications, file types etc.
Give the profile a name and click ok.
Go to your security policies under the policies tab and select the policy in which your traffic is hitting. In the actions tab of the selected policy, you can choose your new file blocking profile from the drop down if you select profiles.
Click commit in the top right hand corner to push the changes down to the data plane and make them active.
Let me know if this helps,
Ben
06-16-2017 08:14 AM
Thanks Ben! So this profile when applied should include the Information Fields Required such as:
- Filename
- Content Type
- File Size
- Any reputation scoring
?
Looking to apply this to the perimeter edge mostly to see if someone is downloading exe. files from the web. Much appreciate the prompt response and assist on this. Thank you again!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!