<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NTA Dashboard in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/nta-dashboard/m-p/528828#M3478</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My goal is ingesting the log from my Fortigate for correlation and analyses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm evaluating Pro per TB now, done the configuration already, actually, the log is receiving now.&lt;/P&gt;
&lt;P&gt;Found the new NTA Dashboard, however, it showed No Permission error for some of the Webget like "GB Sent and Received", "Actions", "Recent Threat", "Daily Threats", "Threat Sources"...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has data/graphs for "Top App-IDs", "Transport Protocols Geo Locations" &amp;amp; "Top Geo Locations".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cannot find much details about this NTA Dashboard either in Release note or the Online techdoc.&lt;/P&gt;
&lt;P&gt;Is this *new* NTA Dashboard meant to be for PA firewall only???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I drill to the XQL for the&amp;nbsp;"Top App-IDs" webget.&lt;/P&gt;
&lt;P&gt;It's referring to the preset called network_story, what is that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;preset = network_story &lt;BR /&gt;| alter app = arrayindex(action_app_id_transitions ,2)&lt;BR /&gt;| comp count(event_id ) as counter by app&lt;BR /&gt;| sort desc counter &lt;BR /&gt;| limit 10&lt;BR /&gt;| view graph type = pie subtype = full xaxis = app yaxis = counter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have the same issue? Any ideas?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Harrison&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex Data Lake" id="Cortex_Data_Lake"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 06:22:34 GMT</pubDate>
    <dc:creator>SeanDeHarris</dc:creator>
    <dc:date>2023-01-27T06:22:34Z</dc:date>
    <item>
      <title>NTA Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/nta-dashboard/m-p/528828#M3478</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My goal is ingesting the log from my Fortigate for correlation and analyses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm evaluating Pro per TB now, done the configuration already, actually, the log is receiving now.&lt;/P&gt;
&lt;P&gt;Found the new NTA Dashboard, however, it showed No Permission error for some of the Webget like "GB Sent and Received", "Actions", "Recent Threat", "Daily Threats", "Threat Sources"...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has data/graphs for "Top App-IDs", "Transport Protocols Geo Locations" &amp;amp; "Top Geo Locations".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cannot find much details about this NTA Dashboard either in Release note or the Online techdoc.&lt;/P&gt;
&lt;P&gt;Is this *new* NTA Dashboard meant to be for PA firewall only???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I drill to the XQL for the&amp;nbsp;"Top App-IDs" webget.&lt;/P&gt;
&lt;P&gt;It's referring to the preset called network_story, what is that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;preset = network_story &lt;BR /&gt;| alter app = arrayindex(action_app_id_transitions ,2)&lt;BR /&gt;| comp count(event_id ) as counter by app&lt;BR /&gt;| sort desc counter &lt;BR /&gt;| limit 10&lt;BR /&gt;| view graph type = pie subtype = full xaxis = app yaxis = counter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have the same issue? Any ideas?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Harrison&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex Data Lake" id="Cortex_Data_Lake"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 06:22:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/nta-dashboard/m-p/528828#M3478</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2023-01-27T06:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: NTA Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/nta-dashboard/m-p/528864#M3480</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NTA dashboard can pretty much list out every detail related to Network data that is ingested from log sources. However, you are correct on the thought that the GB sent and received is tagged to dataset for PAN NGFW data only.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network story is a preset or a data model which collates all the network related activities collected in cortex xdr in form of EDR data or in form Network data (firewalls, routers, switches, etc.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are trying to monitor your data ingestion into XDR, I recommend you can check ingestion from the data ingestion dashboard. The data ingestion dashboard is agnostic of log sources and can show you the amount of data ingested into CDL to help you calculate your Pro Per TB usage. Example screenshot is below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="" data-file-name="Screenshot 2023-01-27 at 8.54.48 PM.png"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class="" style="width: 100%;"&gt;&lt;SPAN&gt;Hope this helps!&amp;nbsp; Please mark the response as "Accept as Solution" if it resolved your query.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-01-27 at 9.04.17 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47468i62943C537D6E87CE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-01-27 at 9.04.17 PM.png" alt="Screenshot 2023-01-27 at 9.04.17 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/nta-dashboard/m-p/528864#M3480</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-01-27T13:04:39Z</dc:date>
    </item>
  </channel>
</rss>

