- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-25-2022 10:20 PM
Hi,
I am creating a data filtering profile and I want to only allow alert threshold, not to block, so I need to know how much value to add inside.
07-25-2022 11:02 PM
Hello @PPradhan
could you refer to this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldCCAS
In nutshell, set the Block Threshold to 0 and Alert Threshold to non zero value. Alert Threshold tells firewall if it sees a data pattern X number of times within the same session to generate an alert. I would start with value 2 or 3 and tune it up if necessary.
Kind Regards
Pavel
07-26-2022 12:28 AM
Thank you for reply @PPradhan
this is correct. Alert means traffic is allowed, only log is generated. Here is a reference to the documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles#id6272be37-1ce2-...
Kind Regards
Pavel
07-25-2022 11:02 PM
Hello @PPradhan
could you refer to this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldCCAS
In nutshell, set the Block Threshold to 0 and Alert Threshold to non zero value. Alert Threshold tells firewall if it sees a data pattern X number of times within the same session to generate an alert. I would start with value 2 or 3 and tune it up if necessary.
Kind Regards
Pavel
07-25-2022 11:52 PM
Hi PavelK,
I have created data patterns profile and data filtering profile and keep threshold alerts to 20, block to 0 and severity to low and added inside the security rule.
>> In monitor > Data Filtering tab I can see the logs are coming and its showing alerts so in that case the traffic is not blocked?
07-26-2022 12:28 AM
Thank you for reply @PPradhan
this is correct. Alert means traffic is allowed, only log is generated. Here is a reference to the documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles#id6272be37-1ce2-...
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!