Newly Observed Palo Alto Network Alert

This rule detects Palo Alto Network alerts that are observed for the first time in the previous 5 days of alert history. Analysts can use this to prioritize triage and response.

Elastic rule (View on GitHub)

 1[metadata]
 2creation_date = "2026/01/21"
 3integration = ["panw"]
 4maturity = "production"
 5updated_date = "2026/07/20"
 6
 7[rule]
 8author = ["Elastic"]
 9description = """
10This rule detects Palo Alto Network alerts that are observed for the first time in the previous 5 days of alert history.
11Analysts can use this to prioritize triage and response.
12"""
13from = "now-7205m"
14interval = "5m"
15language = "esql"
16license = "Elastic License v2"
17name = "Newly Observed Palo Alto Network Alert"
18risk_score = 99
19rule_id = "283683eb-f2ce-40a5-be16-fa931cb5f504"
20severity = "critical"
21tags = ["Use Case: Threat Detection", "Rule Type: Higher-Order Rule", "Resources: Investigation Guide", "Domain: Network", "Data Source: PAN-OS"]
22timestamp_override = "event.ingested"
23type = "esql"
24
25query = '''
26FROM logs-panw.panos-*, filebeat-* metadata _id
27
28// exclude Informational and Low severity levels (4 and 5)
29| where data_stream.dataset == "panw.panos" and
30        TO_INTEGER(event.severity) <= 3 and
31        event.action != "flood_detected" and
32        (event.kind IS NULL or event.kind != "metric")
33
34| STATS Esql.alerts_count = count(*),
35        Esql.first_time_seen = MIN(@timestamp),
36        Esql.distinct_count_src_ip = COUNT_DISTINCT(source.ip),
37        Esql.distinct_count_dst_ip = COUNT_DISTINCT(destination.ip),
38        src_ip = VALUES(source.ip),
39        dst_ip = VALUES(destination.ip),
40        url_dom = VALUES(url.domain),
41        url_path = VALUES(url.path) by rule.name, event.action, event.type, event.kind, event.severity
42
43// first time seen is within 10m of the rule execution time within last 5 days
44| eval Esql.recent = DATE_DIFF("minute", Esql.first_time_seen, now())
45| where Esql.recent <= 10 and Esql.alerts_count <= 5 and Esql.distinct_count_src_ip <= 2 and Esql.distinct_count_dst_ip <= 2
46
47// move dynamic fields to ECS quivalent for rule exceptions
48| eval source.ip = MV_FIRST(src_ip),
49       destination.ip = MV_FIRST(dst_ip),
50       url.domain = MV_FIRST(url_dom),
51       url.path = MV_FIRST(url_path)
52| keep rule.name, event.*, Esql.*, source.ip, destination.ip, url.domain, url.path
53'''
54note = """## Triage and analysis
55
56### Investigating Newly Observed Palo Alto Network Alert
57
58This rule surfaces newly observed, low-frequency high severity Palo Alto Network alert within the last 5 days.
59
60Because the alert has not been seen previously for this rule and host, it should be prioritized for validation to determine
61whether it represents a true compromise or rare benign activity.
62
63### Investigation Steps
64
65- Identify the source address, affected host and review the associated rule name to understand the behavior that triggered the alert.
66- Validate the source address under which the activity occurred and assess whether it aligns with normal behavior.
67- Refer to the specific alert details like event.original to get more context.
68
69### False Positive Considerations
70
71- Vulnerability scanners and pentesting.
72- Administrative scripts or automation tools can trigger detections when first introduced.
73- Development or testing environments may produce one-off behaviors that resemble malicious techniques.
74
75### Response and Remediation
76
77- If the activity is confirmed malicious, isolate the affected host to prevent further execution or lateral movement.
78- Terminate malicious processes and remove any dropped files or persistence mechanisms.
79- Collect forensic artifacts to understand initial access and execution flow.
80- Patch or remediate any vulnerabilities or misconfigurations that enabled the behavior.
81- If benign, document the finding and consider tuning or exception handling to reduce future noise.
82- Continue monitoring the host and environment for recurrence of the behavior or related alerts."""
83references = ["https://www.elastic.co/docs/reference/integrations/panw"]

Triage and analysis

Investigating Newly Observed Palo Alto Network Alert

This rule surfaces newly observed, low-frequency high severity Palo Alto Network alert within the last 5 days.

Because the alert has not been seen previously for this rule and host, it should be prioritized for validation to determine whether it represents a true compromise or rare benign activity.

Investigation Steps

  • Identify the source address, affected host and review the associated rule name to understand the behavior that triggered the alert.
  • Validate the source address under which the activity occurred and assess whether it aligns with normal behavior.
  • Refer to the specific alert details like event.original to get more context.

False Positive Considerations

  • Vulnerability scanners and pentesting.
  • Administrative scripts or automation tools can trigger detections when first introduced.
  • Development or testing environments may produce one-off behaviors that resemble malicious techniques.

Response and Remediation

  • If the activity is confirmed malicious, isolate the affected host to prevent further execution or lateral movement.
  • Terminate malicious processes and remove any dropped files or persistence mechanisms.
  • Collect forensic artifacts to understand initial access and execution flow.
  • Patch or remediate any vulnerabilities or misconfigurations that enabled the behavior.
  • If benign, document the finding and consider tuning or exception handling to reduce future noise.
  • Continue monitoring the host and environment for recurrence of the behavior or related alerts.

References

Related rules

to-top