User Tools

Site Tools


paloaltonetworks:logs:threat-logs

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
paloaltonetworks:logs:threat-logs [2020/08/10 16:09] – [Triggered by Zone Protection Profile] bstaffordpaloaltonetworks:logs:threat-logs [2022/11/23 12:49] (current) – external edit 127.0.0.1
Line 6: Line 6:
 ===== Threats ===== ===== Threats =====
 <code>( subtype eq wildfire-virus ) and ( severity eq medium )</code> <code>( subtype eq wildfire-virus ) and ( severity eq medium )</code>
 +<code>( subtype eq ml-virus ) and ( severity eq medium )</code>
 <code>( subtype eq virus ) and ( severity eq medium )</code> <code>( subtype eq virus ) and ( severity eq medium )</code>
 <code>( subtype eq spyware ) and ( action eq sinkhole )</code> <code>( subtype eq spyware ) and ( action eq sinkhole )</code>
Line 35: Line 36:
 <code>( subtype eq flood ) and ( name-of-threatid eq 'TCP Flood' ) and ( action eq drop ) and ( severity eq critical )</code> <code>( subtype eq flood ) and ( name-of-threatid eq 'TCP Flood' ) and ( action eq drop ) and ( severity eq critical )</code>
 <code>( subtype eq flood ) and ( name-of-threatid eq 'ICMP Flood' ) and ( action eq drop ) and ( severity eq critical )</code> <code>( subtype eq flood ) and ( name-of-threatid eq 'ICMP Flood' ) and ( action eq drop ) and ( severity eq critical )</code>
 +===== DoS Protection Profile/Policy ===== 
 +<code>( subtype eq flood ) and (name-of-threatid eq 'Session Limit Event') and ( action eq drop ) and ( severity eq critical )</code>
  
paloaltonetworks/logs/threat-logs.1597075789.txt.gz · Last modified: (external edit)