<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble doing ML on security policy from panorama? in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221547#M276</link>
    <description>&lt;P&gt;Im running 1.0.99.1 . I did get syslog working,&amp;nbsp; I had to rename my log files to csv,&amp;nbsp; I can now run ML and RE but there is no ouput after it is done.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2018 16:30:10 GMT</pubDate>
    <dc:creator>devincallaway</dc:creator>
    <dc:date>2018-07-10T16:30:10Z</dc:date>
    <item>
      <title>Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221339#M271</link>
      <description>&lt;P&gt;Can you use the ML and rule enhancements on security policy that is located in panorama.&amp;nbsp; Im struggling a bit to get it to work.&amp;nbsp; I set my project up to use panorama and then brought in the firewalls.&amp;nbsp; There is not a schedule log export function to panorama to csv so I am exporting from firewall.&amp;nbsp; I tried fwd syslog but the tool did not recognize the files.&amp;nbsp; I get deferent results if i point my log connecter to panorama or the firewall.&amp;nbsp; I get &lt;STRONG&gt;no devices in this connector&lt;/STRONG&gt; If I point it at the firewall I&amp;nbsp;&amp;nbsp; If point the connector at the firewall I get &lt;STRONG&gt;No rules selected for learning.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are some screenshots. Thanks for you help in advance: I did the lab at ignite and am really excited about this tool,&amp;nbsp; I'm a partner and plan on demoing it at one of our customer events in a couple of weeks.&amp;nbsp; I would really like to do it on panorama and a larger firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firewallconn.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15831iCD6C8C6039BA8B2B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="firewallconn.png" alt="firewallconn.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firewalloutput.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15834iB490C09FD0B34068/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="firewalloutput.png" alt="firewalloutput.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panoramaOutput.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15833i7FB6DAE3BE918546/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panoramaOutput.png" alt="panoramaOutput.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panoramaconn.png" style="width: 627px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15832iD33925A5BE6F0881/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panoramaconn.png" alt="panoramaconn.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 23:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221339#M271</guid>
      <dc:creator>devincallaway</dc:creator>
      <dc:date>2018-07-09T23:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221510#M275</link>
      <description>&lt;P&gt;What version of Expedition are you using?&amp;nbsp; I had the same issue, but it resolved itself when I upgraded to 1.0.99.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 15:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221510#M275</guid>
      <dc:creator>Esfeld</dc:creator>
      <dc:date>2018-07-10T15:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221547#M276</link>
      <description>&lt;P&gt;Im running 1.0.99.1 . I did get syslog working,&amp;nbsp; I had to rename my log files to csv,&amp;nbsp; I can now run ML and RE but there is no ouput after it is done.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 16:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221547#M276</guid>
      <dc:creator>devincallaway</dc:creator>
      <dc:date>2018-07-10T16:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221589#M280</link>
      <description>&lt;P&gt;Yes, it is possible, but a couple of things which may get tricky:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As we are going to work from a policy located in the Panorama device, we need to import the Panorama config.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The config should come from a device registered in Expedition. Uploading the Panorama XML config is not supported yet.&lt;/LI&gt;
&lt;LI&gt;We need to have connectivity to Panorama JUST to retrieve the connected devices. In order to know which serials we are going to learn from (the managed devices) we need to have them registered&lt;/LI&gt;
&lt;LI&gt;We will do the log connector using Panorama as a source, selecting the desired DG and selecting the desired fw-vsys's.&lt;/LI&gt;
&lt;LI&gt;The rules we flag for learning, SHOULD be from the Panorama source.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I hope this helps. If not, we could have a Zoom session to check it in detail.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 17:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221589#M280</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2018-07-10T17:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221590#M281</link>
      <description>&lt;P&gt;Yes, it is possible, but a couple of things which may get tricky:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As we are going to work from a policy located in the Panorama device, we need to import the Panorama config.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The config should come from a device registered in Expedition. Uploading the Panorama XML config is not supported yet.&lt;/LI&gt;
&lt;LI&gt;We need to have connectivity to Panorama JUST to retrieve the connected devices. In order to know which serials we are going to learn from (the managed devices) we need to have them registered&lt;/LI&gt;
&lt;LI&gt;We will do the log connector using Panorama as a source, selecting the desired DG and selecting the desired fw-vsys's.&lt;/LI&gt;
&lt;LI&gt;The rules we flag for learning, SHOULD be from the Panorama source.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I hope this helps. If not, we could have a Zoom session to check it in detail (fwmigrate at paloaltonetworks dot com).&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 17:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/221590#M281</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2018-07-10T17:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/227033#M378</link>
      <description>&lt;P&gt;I get the same as described above and I'm running 1.0.101&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 14:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/227033#M378</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2018-08-14T14:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/227580#M384</link>
      <description>&lt;P&gt;Hi Esfeld, could you tell me how to upgrade the Tool ? I could not find a reference in the Admin/User Guides and "sudo apt-get update &amp;amp;&amp;amp; apt-get upgrade" does not seem to work. &lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 08:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/227580#M384</guid>
      <dc:creator>thomas.busse</dc:creator>
      <dc:date>2018-08-20T08:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/227623#M386</link>
      <description>&lt;P&gt;Those are the correct commands to run for it to get the updates.&amp;nbsp; Make sure it is allowed through your firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 16:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/227623#M386</guid>
      <dc:creator>Esfeld</dc:creator>
      <dc:date>2018-08-20T16:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble doing ML on security policy from panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/228350#M401</link>
      <description>&lt;PRE&gt;sudo apt-get update
sudo apt-get install expedition-beta&lt;/PRE&gt;</description>
      <pubDate>Mon, 27 Aug 2018 08:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/trouble-doing-ml-on-security-policy-from-panorama/m-p/228350#M401</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-08-27T08:54:29Z</dc:date>
    </item>
  </channel>
</rss>

