Question about Paloalto External Dynamic List

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Question about Paloalto External Dynamic List

L3 Networker

Hello all,

I hope you are doing well : )

I recently received an EDL-related question from a customer, but I couldn't find an answer, so I want to ask for advice.

The customer's configuration is the configuration set by the blacklist IP on the EDL

However, the blacklist IP should be checked in the traffic log, but it can be checked in the treatment log.


Is this expected action?

Then can you tell me why the log is recorded in the Treat log tab?

 

(EDL)

스크린샷 2022-10-19 오후 5.12.57.png

(Security Policy)

스크린샷 2022-10-19 오후 5.13.09.png

(Treat log)

스크린샷 2022-10-19 오후 5.20.48.png


Thanks!

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello,

I would suggest they use the 'Unified' log. This shows all the other logs all together. I find its more helpful than jumping from different logs, etc.

Another thing they could try is to put a 'Tag' on the policy that utilizes the EDL. This way they can just filter by the 'Tag'

 

Regards,

 

@OtakarKlier 

Thank you for sharing the information.

If so, is it normal work for the IPs set in the EDL to be logged in the Treat log?

Cyber Elite
Cyber Elite

Hello,

I honestly do not know, but would be nice if someone who does can chime in @kiwi  or @reaper ?

I would only speculate that if the EDL is in a DENY policy, it would show up in the threat logs.

 

Regards,

@OtakarKlier
Thank you for replying 
.
I have tested EDL in a DENY rule, it is displayed in the Traffic logs.

  • 1375 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!