- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Can we export DNS domains or hostnames from Th...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can we export DNS domains or hostnames from Threat prevention report to sinkhole?
Hi There,
I am seeing lot of DNS requests are being detected hence wondering if we can export those domain names or hostnames in CSV format so that those can be sinkhole or how can I put those queries in Prevent mode since I am not seeing any Policy for blocking DNS requests.
Thanks and Regards,
Blason R
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can probably take the relevant log entries and export them with SmartView.
Write a script to pull out the domains and either:
- Add them to your Threat Prevention profile via the APIs
- Create a custom feed that your gateways import with this data, e.g. What is "Custom Intelligence Feeds" feature?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nah that is not happening..Smart log in R80.x only allows to export 50 entries while Smart View does not give option to filter the logs based on Protection.
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In any case, we don't allow export of data directly from ThreatCloud.
SmartLog will allow export of more than 50 lines, you just have to make the logs visible first
Even so, you could probably take fw log output of the relevant log, "grep" for the data you want, then process it as above.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes that's what I need to do by using bash scripts!! Thanks for the help
Blason R
CCSA,CCSE,CCCS
