Virus/spware download blocked but no threat logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Virus/spware download blocked but no threat logs

L3 Networker

Hi

 

When users are accessing internal portal then they are getting "Virus/spware  download blocked" on browser with file name (althrough they are not accessing this file) but there is no virus/spyware logs in threat monitor tab.

 

Any pointers how to fix this?

5 REPLIES 5

Cyber Elite
Cyber Elite

You have identified that this block page is presented by Palo?

All your security policies have "Log at Session End" checked on Actions tab?

Do you see those threat events in ACC? Be aware ACC has 15 minute delay.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

@Raido_Rattameister thanks. 

 

You have identified that this block page is presented by Palo? 

Yes becuase it is the default block page by Palo Alto firewall 

 

All your security policies have "Log at Session End" checked on Actions tab? Yes  I double checked that

Do you see those threat events in ACC? Be aware ACC has 15 minute delay. 

I cannot see this here but I can see "others" with count 10

Cyber Elite
Cyber Elite

@faizankhurshid,

Have you taken a packet capture of the effected machine just to verify that they truthfully aren't trying to access the file-name indicated? It could be that the machine is infected with spyware/malware and they are trying to inject something into the browser page, or that they are getting redirected to a download page other than the page they were hoping to go to? 

@BPry thanks but why I am not getting threat logs for this 😞

@faizankhurshid,

That would depend on your configuration; what does your security profile assigned actually look like? 

  • 4081 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!