Scanning network flow using file name

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Scanning network flow using file name

L3 Networker


Any know an opportunity to scan network flow with PaloAlto to find files by file name? Eg.: i entered "angry tiger" and i find all files (including all file types) with that name sent over the network.


Accepted Solutions

I found one solution: i must log all file types using File Blocking profile (File Type -> any, Action -> alert) and then in a Data Filtering log i can find file using file name. Not ideal, but works Smiley Happy

View solution in original post


L4 Transporter


We see that you are looking for certain text and you are receiving all files with all file types. If there is a filter to be made for certain file types we will have to use the file blocking profile as explained below.

You can also create custom vulnerability by creating custom signature for matching a certain pattern of text in files so that the PAN can search for these texts and when matches logs with the custom vulnerability on the device.


Thanks for answers. So as i understand, no way to find file using file name. Or anyone has other ideas?

Let me explain more what i want: If someone sent a file: angry_tiger.doc or angry_tiger.mp3, or angry_tiger.avi, or angry_tiger.*(any file type). Can i some how find that file using file name "angry_tiger"?

Please follow below mentioned discussion for more info:

Hope it helps.


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!