<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Real-time update tab in Devices in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/388558#M3183</link>
    <description>&lt;P&gt;Hi is there an update to whether this is available on 9.x of PAN-OS or available now with the latest release of expedition?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Mar 2021 10:23:35 GMT</pubDate>
    <dc:creator>jasonwa</dc:creator>
    <dc:date>2021-03-02T10:23:35Z</dc:date>
    <item>
      <title>Real-time update tab in Devices</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/247136#M1050</link>
      <description>&lt;P&gt;Under a device in Expedition there is a tab called Real-time updates. It seems to be a syslog receiver for changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone confirm how to use this feature?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 13:09:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/247136#M1050</guid>
      <dc:creator>rodvand_de</dc:creator>
      <dc:date>2019-01-23T13:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Real-time update tab in Devices</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/247173#M1051</link>
      <description>&lt;P&gt;This feature is not complete, unfortunatelly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;What does feature this do?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Let me explain what it is meant to do when complete:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&amp;nbsp;If you define in your PA to send Config syslog entries to Expedition, Expedition will parse such changes and check which modifications it would require into your policies to keep them in synch.&lt;/LI&gt;
&lt;LI&gt;It will require the System syslog entries as well, to determine when a Commit has been applied and know then that the changes need to me transferrerd into the projects. If the System info would report that you went back to Running Config, the pending changes would be discarded. However, if a specific config is loaded (for instance, a saved config in the PA), the project will get into an unsynch state, as we would not know which changes are present in the new config.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Notice that the controls to keep the projects in synch with the policies are very complex. We need to identify which objects are changing, which rules are being modified or moved, etc. and to know how would that effect to the current changes that you may have in the Expedition project.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's&amp;nbsp;put one example:&lt;/P&gt;
&lt;P&gt;Imagine you decided to delete an address object in the Expedition project, because you are doing some cleaning (you decided that using a range instead of multiple IP addresses as a source would increase the readability of the config).&lt;/P&gt;
&lt;P&gt;However, somebody in the PA, decided to modify the address object and convert it into a subrange.&lt;/P&gt;
&lt;P&gt;What should Expedition do in such case? Create the address object again? Verify that the new object is still redundant given the changes in your project? Raise a warning because you may overwrite some "interesting" changes in your PA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;In Which state is this feature now?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;We have been covering quite a large subset of these changes, and only for Security Rules and Nat Rules (including address, services, apps, etc.) but there are several features that we have not covered, such as network settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For this reason, this feature has not been promoted and we may retake its implementation for PANOS 9.0, where we expect to be able to track the changes better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="3"&gt;What does it require to activate it?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Take a look into the rsyslog file in&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;/var/www/html/OS/rsyslog/rsyslog.conf&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;You will see that this config in rsyslog has a logic to identify different types of Config and System syslog actions, and executes some database inserts to report seen config modifications. It requires of the module&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;mmnormalize&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;to know how to read the syslog messages, which are defined in&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;/var/www/html/OS/rsyslog/palo_alto_networks.rb&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;However, we will have to&amp;nbsp;extend thaose schemas to support PANOS 9.0 when we retake this task, as we were doing this implementation during PANOS 7.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="3"&gt;I want to help&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Suggestions or coding hands will be welcome to help into this feature completeness. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You can contact us at fwmigrate at paloaltonetworks dot com or directly to me at dgildelaig at paloaltonetworks dot com&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 16:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/247173#M1051</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2019-01-23T16:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Real-time update tab in Devices</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/388558#M3183</link>
      <description>&lt;P&gt;Hi is there an update to whether this is available on 9.x of PAN-OS or available now with the latest release of expedition?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 10:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/real-time-update-tab-in-devices/m-p/388558#M3183</guid>
      <dc:creator>jasonwa</dc:creator>
      <dc:date>2021-03-02T10:23:35Z</dc:date>
    </item>
  </channel>
</rss>

