Showing results for 
Search instead for 
Did you mean: 

Firewall Data Collection

I have a team member looking for an answer to this question:

.  I’m looking at Rule “User Accessed URL” (Signature ID: 278-304001) and I have to dive into the Packet detail to retrieve this detail.  Would it be possible to move this data into a normalized field automatically?

2 Replies

Re: Firewall Data Collection

Yes, you could re-write the parser rule and disable the old one, if it is using an ASP parser.

Re: Firewall Data Collection

Yes, it is using pix\asa (asp)