Session end reason as "Threat" in traffic logs, but no threat log generated for DNS traffic dropped by Anti-Spyware profile
3490
Created On 03/06/25 15:39 PM - Last Modified 10/21/25 08:13 AM
Symptom
- In the traffic logs the session end reason is "Threat".
- In the threat logs no related logs are seen.
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- DNS policies - Anti-Spyware profile
Cause
A possible cause is, the workaround of CVE-2024-3393 (e.g. DNS Security Severity Logging to "None") is applied and the settings are not reverted back after applying the fix of the vulnerability.
In this case, customer will continue to see "Session End Reason - Threat" since the DNS Policies in the Anti-Spyware profile will continue to enforce action, but there won't be any threat logs for DNS security flagged domains.
- Confirm if logging is enabled for Security profile - Anti-Spyware profile - DNS policies
- The below capture shows a configuration where the logging is disabled for DNS policies.
Resolution
Follow the below steps to enable logging on each of the DNS security components to generate threat logs for the traffic being matched.
- Click on the Log severity dropdown for each component
- Select the default severity or any other severity desired for the threat log
- Commit