Focus
Focus
Table of Contents

Threats Permitted

Identifies threatening network traffic the firewall failed to block. Collects threat summary log records where the threat type was virus, vulnerability, wildfire-virus, or spyware; the threat severity was greater than or equal to medium; and the firewall's action was only to raise an alert.

Metric Details

Category
Threat Prevention
Daily
Telemetry Tier
Full
Equivalent CLI Command
ROOT: pan_logquery -b -t thsum -q '(action eq alert) and (severity geq medium) and ( (threat-type eq virus) or (threat-type eq vulnerability) or (threat-type eq wildfire-virus) or (threat-type eq spyware) )' -n 5000 -e last-24-hrs