Our product detects malware in network traffic streams (the product does not really matter here). When we generate what we call an event, we know the source/destination ip/port. We have had some customers ask for automatically putting the external (usualy the source) ip address on a block list. the list of blocked ip's will of course grow over time. Of course i'm totaly new to Palo Alto, so i'm not sure what the best way to automate adding an ip to a block list. In some ways, one could consider our product as a block list feed, but i'm wondering a) is a block list feed the right way, or is there a better way to add to a list of ip's to block b)what the appropriate api calls would be to accomplish this. Any examples, or other pointers would be much appreciated
... View more