<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama configuration device log in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326498#M2562</link>
    <description>&lt;P&gt;I managing all firewalls in panorama, with all rules in devicegroups and none local rules. Is it possible to use panorama configuration in expedition but forwarding logs from the firewalls ? That way I save disk space on the expedition server by only sending the logs from the firewalls I want to use the expedition for and not the complete log from panorama log collector.&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 19:32:13 GMT</pubDate>
    <dc:creator>mrkaccount</dc:creator>
    <dc:date>2020-05-06T19:32:13Z</dc:date>
    <item>
      <title>Panorama configuration device log</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326498#M2562</link>
      <description>&lt;P&gt;I managing all firewalls in panorama, with all rules in devicegroups and none local rules. Is it possible to use panorama configuration in expedition but forwarding logs from the firewalls ? That way I save disk space on the expedition server by only sending the logs from the firewalls I want to use the expedition for and not the complete log from panorama log collector.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 19:32:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326498#M2562</guid>
      <dc:creator>mrkaccount</dc:creator>
      <dc:date>2020-05-06T19:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama configuration device log</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326537#M2563</link>
      <description>&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Hi Mrkaccount,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L0-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp;In Expedition, you can add either Panorama or firewall as log connector.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 20:14:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326537#M2563</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-05-06T20:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama configuration device log</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326584#M2564</link>
      <description>&lt;P&gt;Yes but can you combine, firewall logs with a panorama configuration. the reason I ask is that RE analysis on some rules has empty results even though the firewall log has a lot of entries for those same rules.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 06:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326584#M2564</guid>
      <dc:creator>mrkaccount</dc:creator>
      <dc:date>2020-05-07T06:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama configuration device log</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326608#M2567</link>
      <description>&lt;P&gt;Sure, you can combine both.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The idea is, as you have the whole configuration managed by panorama, you would create a project importing the Panorama configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure that you have declared the Panorama as a device in Expedition and that you link this Panorama to your project. Is using this Panorama that you will import the config into the project.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Declare a log connector in your project that uses the Panorama, the specific source you are checking (in case you have imported the Panorama configuration more than once, the device group that your firewalls hang from and, within the Device Group, select the firewalls that should have been seeing the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the "mapping" that we can do to relate security rules in a Panorama configuration with the traffic reported by the NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the device list, you should still be able to pre-process the CSV traffic files that the NGFW are sending to your Expedition.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 08:19:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326608#M2567</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-05-07T08:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama configuration device log</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326644#M2571</link>
      <description>&lt;P&gt;I also thought that was the general idea, thank you so much for clarifying.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 13:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-configuration-device-log/m-p/326644#M2571</guid>
      <dc:creator>mrkaccount</dc:creator>
      <dc:date>2020-05-07T13:19:00Z</dc:date>
    </item>
  </channel>
</rss>

