- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-22-2015 05:30 AM
I thought that was going to be the case but my boss asked me to investigate and I was unable to find a way to do it that is why I posted on this board
07-22-2015 05:34 AM
I think maybe his boss is worried about storage retention, just guessing, that's why he's trying to not even send certain ones. The point of the SIEM though is to have all logs and let the correlation engine decide based upon all possible related information to bring to the front the most relevant logs.
07-22-2015 05:36 AM
No actually I think my boss is trying to find out all the PA can do and use it to its fullest extent
07-22-2015 05:43 AM
Following what you were asking before:
Sending filters that you establish from the threat logs to your syslog SIEM:
IE..( subtype eq vulnerability ) and ( threatid eq 34804 ) and ( app eq web-browsing ) and ( action eq alert ) and ( severity eq medium ) and ( rule eq 'OBB - Alw Guest Netwrk to Inet' )
What would be the point of sending this specifically? Wouldn't it just be easier to use the native functions within the respective tools? IE...the "clickable" filtering in the Palo UI and the regex parsing within your SIEM?
07-22-2015 05:46 AM
I don't know just trying to do what my boss asked. So I will just tell him that it has to be done on the seim side
07-22-2015 05:49 AM
jprovineIf I am understanding your question properly to get more granular you could create a rule that only has a vulnerability profile assigned to it and forward to your SIEM. With a custom vulnerability profile you could get granular too. I may be misinterpreting what you are looking to do and disregard if I am missing your objective.
07-22-2015 05:51 AM
That is a very interesting thought
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!