08-19-2013 06:52 AM
Hello,
Any know an opportunity to scan network flow with PaloAlto to find files by file name? Eg.: i entered "angry tiger" and i find all files (including all file types) with that name sent over the network.
08-20-2013 01:37 AM
Hi,
If you want to search file name, you ave to go through data filtering profile.
The easiest way to do it is to use regex? With this method you can search all what you want.
Eg: https://live.paloaltonetworks.com/docs/DOC-4860.
Just keep in mind that you can't search string with size under 7.
Hope help.
V.
08-20-2013 03:22 AM
I found one solution: i must log all file types using File Blocking profile (File Type -> any, Action -> alert) and then in a Data Filtering log i can find file using file name. Not ideal, but works
08-20-2013 03:31 AM
Hi,
yes you can do that, very usefull for auditing 🙂
Maybe upload logs to syslog server and make a script for sending an alert
V.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!