<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition unable to process security rule for Rule Enrichment in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/330474#M2621</link>
    <description>&lt;P&gt;Anyone please?&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2020 09:05:25 GMT</pubDate>
    <dc:creator>jamesshelley</dc:creator>
    <dc:date>2020-05-29T09:05:25Z</dc:date>
    <item>
      <title>Expedition unable to process security rule for Rule Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/329437#M2615</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm working with a customer who has Expedition installed on their network on Ubuntu 16.04. Expedition is on the latest version (1.1.68).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've setup a traffic log forwarder from one of their firewalls which connects to their Expedition just fine. I've added their Panorama device, pulled in the managed devices and running config. I've processed the logs in /home/expedition/logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've created a new project, imported the config and created a log connector for the last 7 days. But whenever I try to run Rule Enrichment on a security rule and hit process it stalls and nothing happens. I've read through the quick start guide which has told me to use this command but it's saying it cannot create connection to the database server, does anyone know how to fix this error?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;####@####:/tmp$ tail PAN_RuleEnrichment.log&lt;BR /&gt;2020-05-22 14:12:40 ERROR RuleAutoCompleter$:812 - Fininshed&lt;BR /&gt;2020-05-22 14:29:50 ERROR RuleAutoCompleter$:810 - Could not create connection to database server.&lt;BR /&gt;2020-05-22 14:29:50 ERROR RuleAutoCompleter$:811 - Log analysis could not be performed. java.lang.ArrayIndexOutOfBoundsException: 92&lt;BR /&gt;2020-05-22 14:29:50 ERROR RuleAutoCompleter$:812 - Fininshed&lt;BR /&gt;2020-05-22 14:45:43 ERROR RuleAutoCompleter$:810 - Could not create connection to database server.&lt;BR /&gt;2020-05-22 14:45:43 ERROR RuleAutoCompleter$:811 - Log analysis could not be performed. java.lang.ArrayIndexOutOfBoundsException: 92&lt;BR /&gt;2020-05-22 14:45:43 ERROR RuleAutoCompleter$:812 - Fininshed&lt;BR /&gt;2020-05-22 14:52:16 ERROR RuleAutoCompleter$:810 - Could not create connection to database server.&lt;BR /&gt;2020-05-22 14:52:16 ERROR RuleAutoCompleter$:811 - Log analysis could not be performed. java.lang.ArrayIndexOutOfBoundsException: 92&lt;BR /&gt;2020-05-22 14:52:16 ERROR RuleAutoCompleter$:812 - Fininshed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 15:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/329437#M2615</guid>
      <dc:creator>jamesshelley</dc:creator>
      <dc:date>2020-05-22T15:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition unable to process security rule for Rule Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/330474#M2621</link>
      <description>&lt;P&gt;Anyone please?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 09:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/330474#M2621</guid>
      <dc:creator>jamesshelley</dc:creator>
      <dc:date>2020-05-29T09:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition unable to process security rule for Rule Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/330537#M2622</link>
      <description>&lt;P&gt;Hi Jamesshelley,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please follow the steps below to see if it helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;1. In ML. Setting, trying to set the Expedition IP to&lt;/SPAN&gt;&lt;STRONG&gt; 127.0.0.1&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt; , this will fall back to Expedition server IP and click “Save”. This step will re-initiate the database connections. (If Expedition is behind a different IP or NATed IP , you would need to put the real IP as ML IP not the NATed IP ) , check the IP using ifconfig. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;2&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;Go to #more /home/userSpace/userDefinitions.php review the parameters in the files look like below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('DBServer' , '127.0.0.1');&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('DBUser',&amp;nbsp; 'root');&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('DBPass', 'paloalto');&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('DBName' ,'project_schema');&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('PARSER_max_execution_time','10000');&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('PARSER_max_execution_memory','1G');&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;define ('DBSQL_LOG_BIN', 0);&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;3. Issue SQL commands to check which IPs were being allowed.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;#&lt;/SPAN&gt;&lt;STRONG&gt;mysql -uroot -ppaloalto&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;expedition@expedition-documentation&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;:&lt;/SPAN&gt;&lt;STRONG&gt;~&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;$ &lt;/SPAN&gt;&lt;STRONG&gt;mysql -uroot -ppaloalto&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Welcome to the MariaDB monitor.&amp;nbsp; Commands end with ; or \g.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Your MariaDB connection id is 319026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server version: 10.1.44-MariaDB-1~xenial mariadb.org binary distribution&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;MariaDB [(none)]&amp;gt; &lt;/SPAN&gt;&lt;STRONG&gt;select host,user from mysql.user;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;+--------------------------+------------------+&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| host &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | user &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;+--------------------------+------------------+&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| &lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;10.8.200.34&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | root&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| 127.0.0.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | root &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| ::1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | root &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| expedition-documentation | root &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| localhost&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | debian-sys-maint |&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;| localhost&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | root &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;+--------------------------+------------------+&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;6 rows in set (0.00 sec)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Verified Expedition IP and User Root is showing up as above&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;4. Check that /etc/mysql/my.cnf is correctly setup not bind to 127.0.0.1. There is a health check in the dashboard that checks this as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Make sure "&lt;STRONG&gt;bind-address&lt;/STRONG&gt; &lt;STRONG&gt;= 127.0.0.1"&lt;/STRONG&gt; is commented out:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;# The following values assume you have at least 32M ram&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;/127.0.0.1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;...skipping&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;# Instead of skip-networking the default is now to listen only on&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;# localhost which is more compatible and is not less secure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;#bind-address&lt;/STRONG&gt; &lt;STRONG&gt;= 127.0.0.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if it helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 16:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/330537#M2622</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2020-05-29T16:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition unable to process security rule for Rule Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/331008#M2631</link>
      <description>&lt;P&gt;It turned out to be the first step that fixed the issue, thanks for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 08:21:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-process-security-rule-for-rule-enrichment/m-p/331008#M2631</guid>
      <dc:creator>jamesshelley</dc:creator>
      <dc:date>2020-06-02T08:21:18Z</dc:date>
    </item>
  </channel>
</rss>

