<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule Enrichment Error in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287349#M1974</link>
    <description>&lt;P&gt;did you have to change the dates in "Time Frame Overrirde"?&lt;/P&gt;
&lt;P&gt;I had to and then analysis started&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2019 12:25:39 GMT</pubDate>
    <dc:creator>GNeyrinck</dc:creator>
    <dc:date>2019-09-09T12:25:39Z</dc:date>
    <item>
      <title>Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/217945#M106</link>
      <description>&lt;P&gt;Anyone have a problem with, when you try to do rule enrichment on a rule(s) that is marked for RE, when you click on "Analyze Data" it says "no rules selected for learning"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule enrichment.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15502i56CC4B2EF93EF25E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule enrichment.PNG" alt="rule enrichment.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 15:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/217945#M106</guid>
      <dc:creator>Tim_Grossner</dc:creator>
      <dc:date>2018-06-14T15:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/217959#M107</link>
      <description>&lt;P&gt;Just found my problem. Wrong device group selected in the log connector. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 17:38:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/217959#M107</guid>
      <dc:creator>Tim_Grossner</dc:creator>
      <dc:date>2018-06-14T17:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/256845#M1377</link>
      <description>&lt;P&gt;Im getting the same error message and my device group is correct in the log collector.&amp;nbsp; Any other suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 20:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/256845#M1377</guid>
      <dc:creator>rohill</dc:creator>
      <dc:date>2019-04-09T20:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/256994#M1380</link>
      <description>&lt;P&gt;The configuration that you are using for the RE needs to come from the device.&lt;/P&gt;
&lt;P&gt;I mean, do not directly upload the XML configuration into a project, but attach a device into the project and use the device as the source for importing the configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may be the reason that provoked that you would get no results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;QUESTION: Why can't I bring the XML manually into the project via the Palo Alto Networks import field?&amp;nbsp;&lt;BR /&gt;ANSWER: When doing Rule Enrichment or Machine Learning processes, we will have to go into the information we learnt from logs. We do need a way to map the security rules to logs that the firewall has generated. We do have a map between logs and devices, as the logs provide the serial number of the device, and we do need to have a mapping between the device and the configuration. This mapping is done by importing the configuration from the device itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;QUESTION: Does this mean that we need to have connectivity to the firewall to download the config?&lt;BR /&gt;ANSWER: Until version 1.1.12, the answer was YES. In 1.1.12 we have provided a functionality to upload the XML config into the device (I refer to the device within Expedition), so you won't need to provide API Keys to do HTTPS connections to the FW and retrieve the XML config.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 14:29:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/256994#M1380</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-04-10T14:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/275491#M1783</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Device imported. Running configuration imported.&lt;/P&gt;
&lt;P&gt;All Policies are there. All Policies are tagged for ML and RE (Monitor&amp;gt;All Rules).&amp;nbsp; But trying to use ML or RE (Analyze Data) gives the same error: "No rules selected for learning".&lt;/P&gt;
&lt;P&gt;What I want to do is - grab seen Source and Destination addresses and Apps in the Traffic logs.&lt;/P&gt;
&lt;P&gt;App ID Adoption &amp;gt; Retrieve Apps (Fast or Slow) is working - so Log Collector Plugin is functioning.&lt;/P&gt;
&lt;P&gt;What mystery is this?&lt;/P&gt;
&lt;P&gt;v. 1.1.23. All internal checks pass.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 07:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/275491#M1783</guid>
      <dc:creator>RMikalauskas</dc:creator>
      <dc:date>2019-07-09T07:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/275492#M1784</link>
      <description>&lt;P&gt;Two things that you could check are:&lt;/P&gt;
&lt;P&gt;- If your configuration is from a Panorama device, the log connector needs to refer to the Panorama device, selecting the desired device group and serial number that applies&lt;/P&gt;
&lt;P&gt;- If you have imported multiple times the same configuration from a firewall (the sources will have the time-stamp in its name), you need to recreate the log connector to make sure that it is using the correct config (even they may have the same config content, their internal IDs are different). This is something that we need to improve in Expedition, so the step is not required.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 07:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/275492#M1784</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-07-09T07:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/275496#M1786</link>
      <description>&lt;P&gt;Thank you. Must have been the second thing. Or somethign else, because I upgraded tool to the 1.1.27 and Imported Device/Config and recreated Project from sratch.&lt;/P&gt;
&lt;P&gt;The error is gone, but there is another thing: after RE analysis is complete - I am presented with 0 results. The table is empty.&lt;/P&gt;
&lt;P&gt;Is there a Time Frame limitation of logs? Mine are about two months old (using custom Time Frame in Log Collector).&lt;/P&gt;
&lt;P&gt;Edit&amp;gt; nope, still no Enrichment or ML data even with fresh logs.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 09:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/275496#M1786</guid>
      <dc:creator>RMikalauskas</dc:creator>
      <dc:date>2019-07-09T09:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/278727#M1819</link>
      <description>&lt;P&gt;There is no limitation software based.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only limitations that we could face are:&lt;/P&gt;
&lt;P&gt;- Bugs in the ML module&lt;/P&gt;
&lt;P&gt;. The HW fails to process all the data while placing it in memory&lt;/P&gt;
&lt;P&gt;- There is no disk space enouigh for hosting all the data while processing&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 18:55:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/278727#M1819</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-07-24T18:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/282786#M1885</link>
      <description>&lt;P&gt;I also have the problem with "no data to display" or "no rules selected for learning" in rule enrichment. I have tried everything suggested in this thread including upgrading to the latest version of Expedition, 1.1.35.&lt;/P&gt;
&lt;P&gt;I have rules tagged for RE. I recreated the connector, I only have one device and no panorama.&amp;nbsp; No dice.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 18:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/282786#M1885</guid>
      <dc:creator>ghalbedel</dc:creator>
      <dc:date>2019-08-14T18:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287336#M1969</link>
      <description>&lt;P&gt;I've deleted all the different imports, unset base config and deleted it.&lt;/P&gt;
&lt;P&gt;I re-loaded the content from the device again -&amp;gt; OK&lt;/P&gt;
&lt;P&gt;Re-configured the log-connector, I'm only having one PA-220, with one VSYS&lt;/P&gt;
&lt;P&gt;I've selected 3 rules on wich I wanted to test the rule Enrichment.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rul_enrichment01.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21308i03628212BB0D2544/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Rul_enrichment01.png" alt="Rul_enrichment01.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I can do an "analysis" but now it's still not showing any output.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 11:53:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287336#M1969</guid>
      <dc:creator>GNeyrinck</dc:creator>
      <dc:date>2019-09-09T11:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287340#M1970</link>
      <description>&lt;P&gt;THe log connector specifies a device that has reported logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you imported those logs into Expedition and have you processed those logs first? And, are the rules that you flagged for RE reported traffic for the selected days in the log connector?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 11:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287340#M1970</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-09-09T11:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287342#M1971</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following logs have been processed:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;root@Expedition:/home/expedition# ls -al /PALogs/&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;total 47612&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;drwxrwxrwx&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;5 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;4096 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;9 06:25 &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;drwxr-xr-x 25 root &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;root &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;4096 Aug 29 09:16 &lt;/SPAN&gt;&lt;SPAN class="s3"&gt;&lt;STRONG&gt;..&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;7555873 Aug 29 21:01 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_08_30_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;12578779 Aug 30 21:01 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_08_31_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;7259591 Aug 31 21:01 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_09_01_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;5756529 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 21:00 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_09_02_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;5795674 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;6 21:00 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_09_07_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;5976994 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;7 21:00 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_09_08_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;3169942 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;8 21:00 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;PA-220_traffic_2019_09_09_last_calendar_day.csv.gz&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;drwxr-xr-x&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;7 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;4096 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;9 06:25 &lt;/SPAN&gt;&lt;SPAN class="s3"&gt;&lt;STRONG&gt;connections.parquet&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-r--r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;623918 Mar&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;2019 &lt;/SPAN&gt;&lt;SPAN class="s4"&gt;&lt;STRONG&gt;iron-skillet-90dev.zip&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;drwxr-xr-x&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;2 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;4096 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;9 06:24 &lt;/SPAN&gt;&lt;SPAN class="s3"&gt;&lt;STRONG&gt;spark-warehouse&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;drwxr-xr-x&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;2 www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;www-data &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;4096 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;9 06:25 &lt;/SPAN&gt;&lt;SPAN class="s3"&gt;&lt;STRONG&gt;sparkLocalDir&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-rw-r--&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;1 expedition expedition &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;17 Sep&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;6 09:48 ssh-export-test.txt&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs_Processed.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21309iADAE670EF6DA8B91/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Logs_Processed.png" alt="Logs_Processed.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I've unset base config after the logs have been processed, but I think that shouldn't really matter?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 12:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287342#M1971</guid>
      <dc:creator>GNeyrinck</dc:creator>
      <dc:date>2019-09-09T12:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287344#M1972</link>
      <description>&lt;P&gt;I've enabled the RE on all rules, and now it's ok I think:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule_enrichment_OK.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21310i620C8A80ACDC538C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Rule_enrichment_OK.png" alt="Rule_enrichment_OK.png" /&gt;&lt;/span&gt;After setting the correct dates can now see this output.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 12:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287344#M1972</guid>
      <dc:creator>GNeyrinck</dc:creator>
      <dc:date>2019-09-09T12:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287348#M1973</link>
      <description>&lt;P&gt;this is now working for me. not sure why. when I open the rule enrichment window in policies there are initially no selected rules showing (but I have selected rules). Previously, when I clicked on "analyze data", I got a pop up that said "no rules selected" or something like. that.&lt;/P&gt;
&lt;P&gt;Now, when I click "analyze data" it does, and then all the selected rules show in the window.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 12:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287348#M1973</guid>
      <dc:creator>ghalbedel</dc:creator>
      <dc:date>2019-09-09T12:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287349#M1974</link>
      <description>&lt;P&gt;did you have to change the dates in "Time Frame Overrirde"?&lt;/P&gt;
&lt;P&gt;I had to and then analysis started&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 12:25:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287349#M1974</guid>
      <dc:creator>GNeyrinck</dc:creator>
      <dc:date>2019-09-09T12:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Enrichment Error</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287352#M1976</link>
      <description>&lt;P&gt;I had tried that previously but nothing happened.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 12:41:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-error/m-p/287352#M1976</guid>
      <dc:creator>ghalbedel</dc:creator>
      <dc:date>2019-09-09T12:41:07Z</dc:date>
    </item>
  </channel>
</rss>

