Threat log

Reply
Highlighted
L2 Linker

Threat log

Hello Team,

 

In the firewall, it is showing around 4000 threat logs of brute force threat and I am receiving 4000 mail in my mailbox.

 

Is there any way for specific threat I will receive only one email

Highlighted
Cyber Elite

As per My experience you can config alerts with severity high or critical.

If any user try to access the same url or file or anyone try brute force attempt you will get email alerts.

 

There is no way as per my knowledge that for any severity Alert you can get only 1 Email alert.

 

MP
Highlighted
Cyber Elite

Hello,

I would recommend sending the logs to your SIEM and set thresholds there. Also you can set the PAN to block these attempts for up to an hour. This is configured in you Anti-spyware policy as well as Zone Protection policy.

 

Regards,

Highlighted
L2 Linker

I want to replicate so please let me how I can configure email forwarding with trail email gateway. Let me know any website providing email gateway trial

Highlighted
Cyber Elite

You can use any website like

yahoo.com

gmail.com

I am using my webmail. shaw.ca as long as you know the email gateway. for example for my email at shaw.ca the email gateway is 

mail.shaw.ca

 

Try this with yahoo.com email address if you have ?

 

MP
Highlighted
L2 Linker

2.PNG1.PNG

Highlighted
Cyber Elite

IT should work as long as email server is reachable and traffic is allowed from your Firewall.

This email alert will go via Management plane of the firewall.

Please check below link

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUiCAK

 

MP
Highlighted
L2 Linker

Tried with yahoo gmail but still getting same issue.

 

Please let me know how i can configure local mail server then i want to use that email server as an gateway or http server will also work to check the behavior of log forwarding

Highlighted
Cyber Elite

My Internet Provider  it works as shown below

 

MP18_0-1577925451823.png

 

 

MP18_0-1577925331318.png

 

 

For Yahoo and Gmail I do not know their settings.

MP
Highlighted
L2 Linker

I tried with yahoo and Gmail but not worked. I tried to create an account in mail.shaw.ca but they need some account number and info. Anyone, please provide mail.shaw.ca account for testing purpose or let me know any other free service provider to replicate the issue

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!