> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-firewall-eal-logs.md).

# Palo Alto Networks Firewall EAL Logs

Alerts related to data source "Palo Alto Networks Firewall EAL Logs".

| Alert                                                                                                                                                                                                                      |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [A rare FTP user has been detected on an existing FTP server](/analytics-alerts/alerts-by-name/a-rare-ftp-user-has-been-detected-on-an-existing-ftp-server.md)                                                             |
| [A user accessed an uncommon AppID](/analytics-alerts/alerts-by-name/a-user-accessed-an-uncommon-appid.md)                                                                                                                 |
| [A user accessed multiple time-consuming websites](/analytics-alerts/alerts-by-name/a-user-accessed-multiple-time-consuming-websites.md)                                                                                   |
| [Abnormal communication with a rare combination of TLS and HTTP User Agent](/analytics-alerts/alerts-by-name/abnormal-communication-with-a-rare-combination-of-tls-and-http-user-agent.md)                                 |
| [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](/analytics-alerts/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server.md) |
| [Abnormal RPC traffic to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-rpc-traffic-to-multiple-hosts.md)                                                                                                       |
| [Abnormal sensitive RPC traffic to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts.md)                                                                                   |
| [Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host](/analytics-alerts/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts-from-a-rarely-seen-host.md)                                   |
| [Bronze-Bit exploit](/analytics-alerts/alerts-by-name/bronze-bit-exploit.md)                                                                                                                                               |
| [DNS Tunneling](/analytics-alerts/alerts-by-name/dns-tunneling.md)                                                                                                                                                         |
| [Failed DNS](/analytics-alerts/alerts-by-name/failed-dns.md)                                                                                                                                                               |
| [Failed Login For a Long Username With Special Characters](/analytics-alerts/alerts-by-name/failed-login-for-a-long-username-with-special-characters.md)                                                                   |
| [FTP Connection Using an Anonymous Login or Default Credentials](/analytics-alerts/alerts-by-name/ftp-connection-using-an-anonymous-login-or-default-credentials.md)                                                       |
| [HTTP with suspicious characteristics](/analytics-alerts/alerts-by-name/http-with-suspicious-characteristics.md)                                                                                                           |
| [Increase in Job-Related Site Visits](/analytics-alerts/alerts-by-name/increase-in-job-related-site-visits.md)                                                                                                             |
| [Massive upload to a rare storage or mail domain](/analytics-alerts/alerts-by-name/massive-upload-to-a-rare-storage-or-mail-domain.md)                                                                                     |
| [Multiple Suspicious FTP Login Attempts](/analytics-alerts/alerts-by-name/multiple-suspicious-ftp-login-attempts.md)                                                                                                       |
| [Multiple uncommon SSH Servers with the same Server host key](/analytics-alerts/alerts-by-name/multiple-uncommon-ssh-servers-with-the-same-server-host-key.md)                                                             |
| [Okta FastPass reported phishing attack suspected](/analytics-alerts/alerts-by-name/okta-fastpass-reported-phishing-attack-suspected.md)                                                                                   |
| [Possible path traversal via HTTP request](/analytics-alerts/alerts-by-name/possible-path-traversal-via-http-request.md)                                                                                                   |
| [Random-Looking Domain Names](/analytics-alerts/alerts-by-name/random-looking-domain-names.md)                                                                                                                             |
| [Rare access to known advertising domains](/analytics-alerts/alerts-by-name/rare-access-to-known-advertising-domains.md)                                                                                                   |
| [Rare DCOM RPC activity](/analytics-alerts/alerts-by-name/rare-dcom-rpc-activity.md)                                                                                                                                       |
| [Rare LDAP enumeration](/analytics-alerts/alerts-by-name/rare-ldap-enumeration.md)                                                                                                                                         |
| [Rare MS-Update Server was detected](/analytics-alerts/alerts-by-name/rare-ms-update-server-was-detected.md)                                                                                                               |
| [Rare MS-Update traffic over HTTP](/analytics-alerts/alerts-by-name/rare-ms-update-traffic-over-http.md)                                                                                                                   |
| [Rare NTLM Usage by User](/analytics-alerts/alerts-by-name/rare-ntlm-usage-by-user.md)                                                                                                                                     |
| [Rare Remote Service (SVCCTL) RPC activity](/analytics-alerts/alerts-by-name/rare-remote-service-svcctl-rpc-activity.md)                                                                                                   |
| [Rare Scheduled Task RPC activity](/analytics-alerts/alerts-by-name/rare-scheduled-task-rpc-activity.md)                                                                                                                   |
| [Rare Scheduled Task RPC activity from a rarely seen host](/analytics-alerts/alerts-by-name/rare-scheduled-task-rpc-activity-from-a-rarely-seen-host.md)                                                                   |
| [Rare Windows Remote Management (WinRM) HTTP Activity](/analytics-alerts/alerts-by-name/rare-windows-remote-management-winrm-http-activity.md)                                                                             |
| [Recurring access to rare domain](/analytics-alerts/alerts-by-name/recurring-access-to-rare-domain.md)                                                                                                                     |
| [Subdomain Fuzzing](/analytics-alerts/alerts-by-name/subdomain-fuzzing.md)                                                                                                                                                 |
| [Suspicious Encrypting File System Remote call (EFSRPC) to domain controller](/analytics-alerts/alerts-by-name/suspicious-encrypting-file-system-remote-call-efsrpc-to-domain-controller.md)                               |
| [Suspicious failed HTTP request - potential Spring4Shell exploit](/analytics-alerts/alerts-by-name/suspicious-failed-http-request-potential-spring4shell-exploit.md)                                                       |
| [Suspicious HTTP parameters detected](/analytics-alerts/alerts-by-name/suspicious-http-parameters-detected.md)                                                                                                             |
| [Suspicious ICMP packet](/analytics-alerts/alerts-by-name/suspicious-icmp-packet.md)                                                                                                                                       |
| [Suspicious NTLM authentication with machine account](/analytics-alerts/alerts-by-name/suspicious-ntlm-authentication-with-machine-account.md)                                                                             |
| [Suspicious SSH Downgrade](/analytics-alerts/alerts-by-name/suspicious-ssh-downgrade.md)                                                                                                                                   |
| [Uncommon WPAD queries](/analytics-alerts/alerts-by-name/uncommon-wpad-queries.md)                                                                                                                                         |
| [Unique client computer model was detected via MS-Update protocol](/analytics-alerts/alerts-by-name/unique-client-computer-model-was-detected-via-ms-update-protocol.md)                                                   |
| [Unusual ADFS Remote Synchronization network connections from non-ADFS server](/analytics-alerts/alerts-by-name/unusual-adfs-remote-synchronization-network-connections-from-non-adfs-server.md)                           |
| [Weakly-Encrypted Kerberos TGT Response](/analytics-alerts/alerts-by-name/weakly-encrypted-kerberos-tgt-response.md)                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-data-source/palo-alto-networks-firewall-eal-logs.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
