- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
07-01-2014 03:53 PM
Hi all,
Please help to config in PAN devices a rule to send alerts to admin when large files, say geq 100Mb, are uploaded to Internet.
Thank you.
07-01-2014 04:04 PM
Hello Dvu5103,
You can create a custom signature for the same:
For an example:
----Go to Object > Custom Objects > Vulnerability and click Add ( Set default action to "alert")
----Go to the Custom Vulnerability Signature > Signatures tab and click Add
----In the window that appears, create a custom signature with 'And condition'.
---In the Standard window, click 'Add Or Condition' and set 'Operator to Greater Than'
---Set an appropriate context.
----You can add this profile in a security profile.
You can post a request to our development team ( Dev-Center), they will be able to help you for the same, else contact with your Palo Alto Networks SE, he will guide you.
Thanks.
07-01-2014 04:04 PM
In order to protect our information, we need to monitor all upload activities to Internet. So it's not possible in PANs ?
Thank you.
07-01-2014 04:09 PM
Thanks, Hulk. I will study your guidance.
07-01-2014 04:36 PM
Hello DVU5103,
It would be hard to specify file size as a parameter in vulnerability custom signature. Hence as HULK said it would be good idea to contact SE.
Regards,
Hardik Shah
07-01-2014 04:53 PM
You can not do alerts, but you can have a daily report for sessions with large data transfers. You will get the information you need the next day.
Go to Monitor > Manage Custom Reports
Add a custom report selecting Database=Traffic Log, Time Frame=Last 24 hours, sort by Bytes, add a query statement with the query builder to have Attribute Bytes, Operator greater or equal than, and add the value.
Then set up your Email Scheduler to have the report be delivered Daily. These will generate every day at 2:02am.
07-01-2014 05:10 PM
Hi Mivaldi,
This appears to be a faster workaround.
Regards,
Hardik Shah
07-01-2014 05:13 PM
Lets try with these available contexts:
This doc will give you some guideline too: Custom Application Signatures
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!