PaloAltoNetworks / SafeNetworking

Read only mirror. To contribute or submit issues, please go to the website link --->
https://gitlab.com/panw-gse/as/SafeNetworking/
Apache License 2.0
12 stars 10 forks source link

Possibility of dynamic traffic logging based on logs from other logging types #53

Open punisherVX opened 5 years ago

punisherVX commented 5 years ago

Need to explore option of dynamically allowing traffic logs for particular end users based on info from other logging types.
As an example, to see what an end user is doing when they have a GTP-in-GTP tunnel (which shows up in GTP logs) we need to have the traffic logs for that end point. However, most traffic logs are useless and take up too much space. So, by dynamically allowing traffic when we trigger on GTP messages would allow us to get the traffic info needed when this happens.