<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues configuring M. Learning while using Panorama for traffic analysis in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316546#M2419</link>
    <description>&lt;P&gt;By green button I'm assuming you mean "Discovery". Then I click Machine Learning.&amp;nbsp; What am I supposed to do after that? Nothing is listed and if I click Analyze Data it appears to get stuck on Initializing and crashes Expedition.&amp;nbsp; Also is "No connector selected" in the picture below normal?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BOkay_0-1584306756459.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24431i72AD24C90E859B37/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="BOkay_0-1584306756459.png" alt="BOkay_0-1584306756459.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 15 Mar 2020 21:17:08 GMT</pubDate>
    <dc:creator>BOkay</dc:creator>
    <dc:date>2020-03-15T21:17:08Z</dc:date>
    <item>
      <title>Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316518#M2417</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to configure M. Learning in Expedition so that we can analyze the traffic passing through specific any any rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We use Panorama to manage the security policy on each of the individual firewalls. Is this an issue when trying to use Machine Learning? Here is the issue I'm running into.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've setup Scheduled Log Exports on each of the individual firewalls to export their logs to Expedition.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Expedition if I add the individual firewall in the Devices tab I can see the csv file and process it in its M.Learning tab. But if I create a project with that firewall I cannot see any of the policy to do a traffic analysis or much of anything else. My assumption is because all that information is being managed at the Panorama level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However. If I add the panorama in the Devices tab and retrieve the specific firewall device and retrieve its configuration, I cannot then process the exported log in the M. Learning tab.&amp;nbsp; I see the files but everything is grayed out and it has a header that says "Process CSV logs can only be executed from FW devices." But when I add the Panorama to a project I can see the entire security policy and everything else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does ML only work in environments where the firewalls aren't centrally managed by Panorama?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 19:13:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316518#M2417</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-15T19:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316524#M2418</link>
      <description>&lt;P&gt;Hello BOkay,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ML works for your environment, you will process logs by going to firewall , when you want to analyze the rules , you will retrieve config from panorama since all your security policy is in panorama, so you will add panorama in your project , import config, next you will need to add panorama as log connector by going to plugin. After all that , you can then go to security policy and select The device group where the rules located then right click Machine Learning , add the selected rule to Machine learning , then click on the machine learning green tab in the bottom to start machine learning.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 19:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316524#M2418</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-15T19:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316546#M2419</link>
      <description>&lt;P&gt;By green button I'm assuming you mean "Discovery". Then I click Machine Learning.&amp;nbsp; What am I supposed to do after that? Nothing is listed and if I click Analyze Data it appears to get stuck on Initializing and crashes Expedition.&amp;nbsp; Also is "No connector selected" in the picture below normal?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BOkay_0-1584306756459.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24431i72AD24C90E859B37/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="BOkay_0-1584306756459.png" alt="BOkay_0-1584306756459.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 21:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316546#M2419</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-15T21:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316550#M2420</link>
      <description>&lt;P&gt;It seems like it did not see any log connector ,when you add log connector under plug in. , you will need to select the corresponding device group.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 22:03:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316550#M2420</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-15T22:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316552#M2421</link>
      <description>&lt;P&gt;Ah I didn't realize you had to pick a active log connector as I had several. I picked the right one and it ran but has No Data even though I know there is traffic data available via Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BOkay_0-1584314344957.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24432i9B3C121F1F17448D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="BOkay_0-1584314344957.png" alt="BOkay_0-1584314344957.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 23:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316552#M2421</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-15T23:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316556#M2422</link>
      <description>&lt;P&gt;Look like from your screenshot you select timeframe was June 2019 , you will make sure the time field of the traffic log you export from firewall to expedition matching the time you specify in the log connector .&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 00:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316556#M2422</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-16T00:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316557#M2423</link>
      <description>&lt;P&gt;It's the same as my log connector. I was just making sure I went back far so that I could get as many logs as possible. You said, "&lt;SPAN&gt;traffic log you export from firewall", however. Did I miss that step? I didn't do any exports, I was under the impression the log connector was all I needed when using panorama. I scheduled the log export to the individual firewalls but that didn't work when using Panorama.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 00:39:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316557#M2423</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-16T00:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316562#M2424</link>
      <description>&lt;P&gt;You could follow the steps in this doc&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/ExpeditionArticles/157/1/Expedition_ver-1.1.0-QuickStart.pdf" target="_blank"&gt;https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/ExpeditionArticles/157/1/Expedition_ver-1.1.0-QuickStart.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 01:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316562#M2424</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-16T01:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316829#M2425</link>
      <description>&lt;P&gt;I followed that document and it puts me in my original situation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I use the individual firewall I have the ability to process the scheduled log exports that are sent to Expedition. But when you start a project and go into the policy the policy is empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I use panorama I lose the ability to process the scheduled log exports as it is all grayed out for the individual firewall. But when I start a project I do have the policy but no mater what log connector I use no rules show up when I click Discovery.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've followed the following guides with no luck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition Migration and Security Assessment Quick Start 1.1.0&lt;/P&gt;
&lt;P&gt;Expedition New Feature: Scheduled Log Processing 1.1.21&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 18:24:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316829#M2425</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-17T18:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316856#M2426</link>
      <description>&lt;P&gt;Hi BOkay,&lt;/P&gt;
&lt;P&gt;Please verify below :&lt;/P&gt;
&lt;P&gt;1. Make sure firewall logs you want to process is located at the path you specified in the M Learning setting, example, here we use /PALogs&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-03-17 at 12.01.52 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24470iD0F0014A077BC9E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-03-17 at 12.01.52 PM.png" alt="Screen Shot 2020-03-17 at 12.01.52 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2. Once you see the files show up in the folder, you will click on Process to process the firewall logs first.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. After all the logs are processed then you will create a new project, and add panorama in the settings of the project like below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-03-17 at 12.08.09 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24471i668F27932D5996C6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-03-17 at 12.08.09 PM.png" alt="Screen Shot 2020-03-17 at 12.08.09 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;4. Go into project, go to plugin , add panorama as log connector , make sure you select the corresponding device group and the firewalls that you processed the logs in step 1, select the timeframe for you traffic logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-03-17 at 12.31.55 PM.png" style="width: 839px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24472i8915B105CF72F858/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-03-17 at 12.31.55 PM.png" alt="Screen Shot 2020-03-17 at 12.31.55 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5. Then goin to policy , continue the ML steps as mentioned in the ML doc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you still need assistance, please write e-mail to &lt;A href="mailto:fwmigrate@paloaltonetworks.com" target="_blank"&gt;fwmigrate@paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 19:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/316856#M2426</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-17T19:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317256#M2438</link>
      <description>&lt;P&gt;If you desire to use ML or RE, we do need to have logs in Expedition.&lt;/P&gt;
&lt;P&gt;ML and RE do a data analytics process on the traffic logs that can't be performed on Panorama or FWs, as they are much more complex than generating reports on the devices.&lt;/P&gt;
&lt;P&gt;Therefore, we need to export the traffic logs into Expedition so we can perform the analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The steps that Lynn showed are required to execute ML or RE. Also, it is very important that the configuration you bring into your project comes from a Device you have declared in Expedition, and not by directly providing an XML to the project. This is necessary because this way we can know the relationship between the security rules you want to analyze (that are declared in a device config) and the traffic logs that the device has provided.&lt;/P&gt;
&lt;P&gt;Notice that the "device" is the link between traffic logs and security rules, therefore we need to import the configuration from the Device&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 09:01:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317256#M2438</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-03-19T09:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317375#M2439</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36606"&gt;@dgildelaig&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem appears to lie in the dynamic between using individual firewalls &amp;amp; panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can only do HALF of the workflows depending on if you import individual firewalls vs panorama.&lt;/P&gt;
&lt;P&gt;You can ONLY do the &lt;EM&gt;first&lt;/EM&gt; half of the workflow if you import individual firewalls.&lt;/P&gt;
&lt;P&gt;You can ONLY do the &lt;EM&gt;second&lt;/EM&gt; half of the workflow if you import panorama.&lt;/P&gt;
&lt;P&gt;But you cannot do it ALL using either method. &lt;U&gt;Meaning you would have to break everything down daily as you get new logs.&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;In the device tab. If you import just the individual firewalls...&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue6.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24537i61CEE0F406B7F93E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Expedition Issue6.png" alt="Expedition Issue6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;You can do the following:&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Go into the individual firewall's M.Learning tab and the Process table is &lt;STRONG&gt;ENABLED&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;You can process the CSV logs.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue7.png" style="width: 956px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24538i36F668D9A7ACBD2C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue7.png" alt="Expedition Issue7.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;U&gt;You can NOT do the following:&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can NOT see any of the security policy once a project is created using the individual firewalls. &lt;FONT color="#FF0000"&gt;&lt;U&gt;This means you cannot do M. Learning traffic analysis.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue8.png" style="width: 840px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24539i1D9DD3533AD4D1BB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue8.png" alt="Expedition Issue8.png" /&gt;&lt;/span&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Now if you import Panorama In the device tab&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Importing Panorama *&lt;STRONG&gt;absorbs*&lt;/STRONG&gt; those individual firewalls. As you can see, the individual firewalls are gone and only panorama remains in the device tab.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue3.png" style="width: 773px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24533iB0C219284900A5C6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue3.png" alt="Expedition Issue3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now things are &lt;U&gt;reversed&lt;/U&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;You can NOT do the following:&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Go into the individual firewall's M.Learning tab and the Process table is &lt;STRONG&gt;DISABLED&lt;/STRONG&gt; and grayed out.&lt;/LI&gt;
&lt;LI&gt;You can no longer process the CSV logs.&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;U&gt;This means we can no longer process new csv logs that will come in.&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue2.png" style="width: 954px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24532i7FC643D48F0357ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue2.png" alt="Expedition Issue2.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;You can do the following:&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Now when you create a project you can now see the security policy, mark rules for M. Learning, and analyze that traffic.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue4.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24534iF2F319D62866716B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue4.png" alt="Expedition Issue4.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue5.png" style="width: 552px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24535i4CB4B372C59E8B13/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue5.png" alt="Expedition Issue5.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This obviously is not a workflow that is practical. If I were to need to do traffic analysis daily I would basically have to break everything down and re-implement everything again.&amp;nbsp; I'd have to do the following daily.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Delete Panorama from the device tab. (because I can no longer process new csv logs)&lt;/LI&gt;
&lt;LI&gt;Add each individual firewall to the device tab.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Do the first half of the workflow. (now I can process new csv logs)&lt;/LI&gt;
&lt;LI&gt;Add Panorama (now those individual firewalls are gone and are absorbed into panorama taking away the ability to process new csv logs)&lt;/LI&gt;
&lt;LI&gt;Do the second half of the workflow.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Now unless there is still something wrong with the way I'm implementing this I think there is a bug. The problem really lies in the disabling of the ability to process CSV Logs to individual firewalls when you are using Panorama.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24536iFF96B12A906908A9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue.png" alt="Expedition Issue.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If "Process CSV logs can only be executed from FW devices." and the grayed out CSV logs were to be removed when using Panorama it should solve everything.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 14:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317375#M2439</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-19T14:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317383#M2440</link>
      <description>&lt;P&gt;From the Panorama device, you can provide a Path for all the firewalls managed by that Panorama.&lt;/P&gt;
&lt;P&gt;If you select to see all the Firewalls, not only the directly connected devices (do it clicking on the three lines icon on the Devices view) you would see all the Firewalls, and you can even select and Autooprocess on the logs, so you do not need to get into them daily.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Later on, in your project, you can import the Panorama config and define in your log connector the Device Group and the devices within that DG for the ML and RE.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 15:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317383#M2440</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-03-19T15:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317390#M2441</link>
      <description>&lt;P&gt;Can you provide a screenshot of what you are referring to? I'm not following.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 15:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317390#M2441</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-19T15:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317399#M2442</link>
      <description>&lt;P&gt;BOkay,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead of add firewall directly to devices, can you only add Panorama as devices, and go to Panorama Device , Click on orange button "Retrieve Connected Devices "&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-03-19 at 8.44.36 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24541iA78D36B06CF042A3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-03-19 at 8.44.36 AM.png" alt="Screen Shot 2020-03-19 at 8.44.36 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you want to process logs , you will then click on the icon on the right upper corner to "show all devices" , and you should see your firewalls , then goin to the firewall to process the ML logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-03-19 at 8.48.31 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24542i3E55B7D8609FFFDC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-03-19 at 8.48.31 AM.png" alt="Screen Shot 2020-03-19 at 8.48.31 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So you do not need to add firewall directly to the devices, just add panorama and retrieved the connected devices, then process the logs in the connected firewall that you got those logs from, make sure the traffic log matched the serial# of the firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After ML log is processed then you can add a new project and continue the steps I mentioned in the previous post.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 16:06:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317399#M2442</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-19T16:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317408#M2443</link>
      <description>&lt;P&gt;Yes, that is what I have outlined. That is not possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I go the route where I go through Panorama via&amp;nbsp;adding Panorama as the device in the Device Tab, Retrieve Contents, Retrieve Connected Devices, Retrieve Contents, and the result is a grayed out M. Learning&amp;nbsp;and the message states "Process CSV logs can only be executed from FW devices."&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Expedition Issue.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24543iF99C93E80F6E486A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Expedition Issue.png" alt="Expedition Issue.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 16:06:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317408#M2443</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-19T16:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317415#M2444</link>
      <description>&lt;P&gt;Which device you click to get to this page , you will need to click on the firewall not the panorama .&amp;nbsp; so important steps is to click on the "Show all devices " on the right upper corner first , then you will able to see connected firewalls.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 16:09:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317415#M2444</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-03-19T16:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317416#M2445</link>
      <description>&lt;P&gt;You may have a Panorama in your Device list.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panorama_device.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24544iC051E0B7CE5A1F80/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panorama_device.png" alt="panorama_device.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you edit it, you can retrieve the connected devices&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panorama_devices_connected_Devices.png" style="width: 971px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24545i59306A70C6979B4B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panorama_devices_connected_Devices.png" alt="panorama_devices_connected_Devices.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And you can also specify where will be the default path where all the managed devices will leave their traffic logs.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panorama_device_ML.png" style="width: 966px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24547i75BD0275910D9E1C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panorama_device_ML.png" alt="panorama_device_ML.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you click on the All Devices icon, you will see that the managed devices are also known in Expedition., and actually, you should be able to see that you can edit them, you can see they inherited the path and you can also mark them for Autoprocessing.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="all_devices.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24549i509B73B9A20A4AF1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="all_devices.png" alt="all_devices.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The specific time when the autoprocessing needs to be performed is in the Settings-&amp;gt;MLearning section.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ml_settings_autoprocess.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24548iEF16B9B1FBA9FDF9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ml_settings_autoprocess.png" alt="ml_settings_autoprocess.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Later on, you would have to bring your Panorama into a project and import its configuration.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-03-19_16-58-26.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24550i52D33BFD8D4D3B43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-03-19_16-58-26.png" alt="2020-03-19_16-58-26.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way, you can create a Log Connector that uses the Panorama Security Rules, and also can access the traffic logs from the managed devices if you select correctly the correct Device Group.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-03-19_16-57-27.png" style="width: 595px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24551i9800225CAD47275C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-03-19_16-57-27.png" alt="2020-03-19_16-57-27.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 16:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317416#M2445</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-03-19T16:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issues configuring M. Learning while using Panorama for traffic analysis</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317497#M2446</link>
      <description>&lt;P&gt;Adding Panorama then that button to show the individual firewalls the last piece of the puzzle I believe. Thank you!!!!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested going through the M. Learning of a few any any rules and I'm seeing good results. There is only one abnormality but I will create a different thread for that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 20:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-configuring-m-learning-while-using-panorama-for-traffic/m-p/317497#M2446</guid>
      <dc:creator>BOkay</dc:creator>
      <dc:date>2020-03-19T20:41:20Z</dc:date>
    </item>
  </channel>
</rss>

