Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
Clear
AutoFocus™ Administrator’s Guide
:
Enable Alerts by Tag Type
Updated on
Tue Jul 26 21:29:53 UTC 2022
Focus
Download PDF
Updated on
Tue Jul 26 21:29:53 UTC 2022
Focus
Home
AutoFocus
AutoFocus™ Administrator’s Guide
AutoFocus Alerts
Create Alerts
Enable Alerts by Tag Type
Download PDF
AutoFocus™ Administrator’s Guide
Enable Alerts by Tag Type
Table of Contents
Filter
Expand all
|
Collapse all
Get Started With AutoFocus
About AutoFocus
Activate AutoFocus Licenses
First Look at the AutoFocus Portal
AutoFocus Concepts
Use AutoFocus with the Palo Alto Networks Firewall
AutoFocus Portal Settings
AutoFocus Dashboard
Dashboard Overview
Set the Dashboard Date Range
Drill Down on Dashboard Widgets
Customize the Dashboard
DNS Security Dashboard
DNS Security Dashboard Overview
DNS Security Dashboard Widgets
AutoFocus Search
Start a Quick Search
Work with the Search
Drill Down in Search Results
Sample
Sessions
Indicators
Set Up Remote Search
Artifact Types
General Artifacts
Sample Artifacts
Session Artifacts
Analysis Artifacts
Linux Artifacts
Windows Artifacts
Mac Artifacts
Android Artifacts
Search Operators and Values
Guidelines for Partial Searches
Contains and Does Not Contain Operators
Proximity Operator
AutoFocus Alerts
Alert Types
Email Alerts
HTTP/HTTPS Alerts
Supported TLS Ciphers
Create Alerts
Define Alert Actions
Enable Alerts by Tag Type
Create Alert Exceptions
View Alerts in AutoFocus
Edit Alerts
AutoFocus Tags
Tag Concepts
Tag Types
Tag Class
Tag Status
Tag Visibility
Tag Group
Tag Details
Create a Tag
Work with Tags
Find Samples by Tag Details
Filter and Sort Tags
Find the Top Tags Detected During a Date Range
Vote for, Comment on, and Report Tags
Assess AutoFocus Artifacts
Find High-Risk Artifacts
Add High-Risk Artifacts to a Search or Export List
Export AutoFocus Content
Export AutoFocus Artifacts
Build an AutoFocus Export List
Create a CSV File
Use Export Lists with the Palo Alto Networks Firewall
Export AutoFocus Page Content
Export AutoFocus Dashboard and Reports
AutoFocus Reports
Reports Overview
Customize Reports
Scheduled Reporting
Use the Threat Summary Report to Observe Malware Trends
Threat Summary Report Overview
View Threat Summary Report Details
AutoFocus Feeds
Feed Overview
Create Custom Feeds
Use AutoFocus Custom Feeds with the Palo Alto Networks Firewall
Manage Custom Feeds
AutoFocus-Hosted MineMeld
Enable Alerts by Tag Type
Enable alerts based on
Tag Types
. You can choose to generate an alert for all samples in your network matched to a tag type. Additionally, you can
Create Alert Exceptions
to set up prioritized alerts for specific tags or to disable alerts for them.
Select
Alerts
Settings
.
If there are no email or HTTP Alert Actions listed,
Define Alert Actions
.
Choose an alert for each tag type.
Use this step at any time to change the alert action for a tag type.
Select an alert
Action
for samples matched to Unit 42, public, and private tags:
Enable the alert for a tag type.
For each tag type, select
Enabled?
to receive alerts when AutoFocus detects samples in your network that match the tag type.
If necessary, specify tags to exclude from the alert for the tag type.
Create Alert Exceptions
in order to:
Create and enable custom alerts for specific tags.
Disable alerts for tags for which you don’t need to receive alerts.
Choose from the following next steps:
Both
Email Alerts
and
HTTP/HTTPS Alerts
list all the samples matched to the alert criteria in the digest period.
View Alerts in AutoFocus
.
You can
Edit Alerts
or
Disable Alerts.
Previous
Define Alert Actions
Next
Create Alert Exceptions