<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: APP-ID adoption doesn't output any app-IDs in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390962#M3232</link>
    <description>&lt;P&gt;Thank you so much for your help &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In summary, (in case anybody else runs into this issue), I first needed to send traffic logs from my devices into Panorama, as the app-id adoption makes a call to Panorama to gather the app-id statistics. Previously I only had my devices sending their traffic logs to Expedition. This worked fine for ML and RE. For APP-ID, the device traffic logs need to be in Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Secondly, Lynn was spot on when she suggested that the log connectors were probably the culprit. I have an Active/Passive pair, and the passive node has a lower serial number than the active node. In the LC, the devices are listed (top-down) based on serial number. The passive node was on top of the Active node (due to the lower serial number). It seems that the LC will check the first device in the list, and if there are no app-id stats, then it won't return anything. As soon as we only selected the active node, the APP-ID stats started working. This is the same with Active/Active devices (if one of the AA devices isn't passing traffic). The device passing traffic must be up top, otherwise you should only select the single device (the device passing traffic) within the LC.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Mar 2021 19:20:47 GMT</pubDate>
    <dc:creator>Eric.Hernandez</dc:creator>
    <dc:date>2021-03-12T19:20:47Z</dc:date>
    <item>
      <title>APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390040#M3212</link>
      <description>&lt;P&gt;&lt;BR /&gt;I'm using expedition 1.1.93&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When I target my any/any rule for app-id adoption, the adoption process finishes, but no app-ids are displayed. This occurs whether I request a slow retrieval or a fast retrieval.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The same rule(s) work fine with ML and RE (app-ids show up as expected).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas? I'm not even sure how to troubleshoot this. Any help is appreciated. Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 17:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390040#M3212</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-09T17:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390047#M3213</link>
      <description>&lt;P&gt;something to add...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Initially I didn't have the "APP-ID via LOG" column showing in the security policies table. I've added that column.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Oddly enough, now when I retrieve apps (fast or slow) the&amp;nbsp;"APP-ID via LOG" column disappears from the table. If I add the column again, it's empty.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 16:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390047#M3213</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-09T16:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390073#M3214</link>
      <description>&lt;DIV class="gmail_default"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138634"&gt;@Eric.Hernandez&lt;/a&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="gmail_default"&gt;For APP-ID Adoption, the important part will be the log connector, please specify the correct PAN-OS device that&amp;nbsp;contains the security policy and logs, make sure Expedition can connect to it via API.&amp;nbsp; To verify that, you can try to click "Retrieve&amp;nbsp;content -&amp;gt; running configuration and see if the latest configuration has been downloaded.&amp;nbsp; For more detailed&amp;nbsp;steps, please review Module 1,2,6,7 of the below video playlist for APP-ID adoptions:&lt;/DIV&gt;
&lt;DIV class="gmail_default"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="gmail_default"&gt;&lt;A href="https://www.youtube.com/playlist?list=PLD6FJ8WNiIqXAfspousboWn6AllrOWVMi" target="_blank"&gt;https://www.youtube.com/playlist?list=PLD6FJ8WNiIqXAfspousboWn6AllrOWVMi&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="gmail_default"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="gmail_default"&gt;Regards,&lt;/DIV&gt;
&lt;DIV class="gmail_default"&gt;Lynn&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Mar 2021 17:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390073#M3214</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-03-09T17:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390098#M3215</link>
      <description>&lt;P&gt;Thank you Lynn.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using Panorama, and I have two log connectors each mapped to their respective device group (and devices).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g.:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LC1 = DG1 = devices 1 and 2&lt;/P&gt;
&lt;P&gt;LC2 = DG2 = devices 3 and 4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could be wrong, but I don't think the log connectors are mis-configure.&amp;nbsp; ML and RE work flawlessly across both DGs (thus invoking both LCs).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any other suggestions or ideas? Thank you again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 19:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390098#M3215</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-09T19:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390100#M3216</link>
      <description>&lt;P&gt;Oddly enough if I exit the project and go into devices, I only see the Panorama device. Retrieving the running configuration of the Panorama device works fine. I can also retrieve connected devices and the content of those devices with no errors.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If I go back into devices and select "show all devices", I now see the FW devices underneath the Panorama instance. If I drill into the FW device directly, and try to retrieve the running config, I receive a remote exception error stating "Please generate an admin API key first".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I was under the impression that I would perform all interaction via Panorama, and that I didn't need to worry about generating API keys at the device level. What do you think?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm going to look through the config logs and see if the admin user pw was changed anywhere.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 19:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390100#M3216</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-09T19:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390103#M3217</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138634"&gt;@Eric.Hernandez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Couple of things you can check :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Where is the security policy defined under?&amp;nbsp; If it's defined in DG1 , the log connector you need to use is LC1,&amp;nbsp; you should delete LC2 since you don't need it for app-id adoption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Is there any traffic logs matching your security policy that you want to analyze for app-id ?&amp;nbsp; Is there app-id shown in the traffic logs?&lt;/P&gt;
&lt;P&gt;3. Make sure your expedition is running the latest version v1.1.92.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. Trying to remove the Panorama from the device tab and re-add it in, re-retrieve the contents and create a new project, assign the panorama to the project, and re-add the log connector.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 20:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390103#M3217</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-03-09T20:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390104#M3218</link>
      <description>&lt;P&gt;If your security policy defined in Panorama, you do not need api key nor connections to firewalls at all.&amp;nbsp; The only interactions is between Expedition and Panorama, please make sure the firewall logs are forwarding to Panorama.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 20:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390104#M3218</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-03-09T20:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390107#M3219</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;I appreciate your help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Without getting too much into design, I have four NGFW devices. Each device pair (HA pair) has it's own device group. There are 'permit any/any' rules within both device groups, and I'd like to analyze all for app-ID adoption.&amp;nbsp; So it's fair to say that I'm&amp;nbsp;attempting app-ID adoption for rules within multiple device groups. This is the reason why I setup two log connectors (one per device group).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. yes, there are traffic logs for the ip any/any rules, and app-IDs are 'seen' within the traffic logs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. I just updated to 1.1.92 this morning&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. (remove Panorama, re-add and re-create project) - I will try this tomorrow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Logs are being shipped from the NGFW devices themselves to the Expedition server via 'scheduled log export'.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for answering my question about connecting via Panorama vs connecting via the devices themselves. Based on your answer, I am doing everything correctly as I can retrieve the connected devices and the connected device content via the 'top level' Panorama device.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My next step (tomorrow) is to delete the project, remove Panorama from the global devices, re-add Panorama, and re-create the project and log connector. I'm confused about&amp;nbsp; this issue as the other features (ML and RE) are currently working fine within this project.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll post here tomorrow after I re-create everything. Thank you again for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 20:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390107#M3219</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-09T20:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390347#M3220</link>
      <description>&lt;P&gt;Today I deleted the project, deleted my panorama device, and deleted all parquet processed logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I re-added the Panorama instance, re-created the project, and recreated the log connectors.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After processing logs, I'm getting the same exact symptoms. ML and RE works fine, both display the expected apps for my PERMIT any/any rule. When I try to retrieve apps for APP-ID adoption (within my any/any rule), nothing shows up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a log that I can look at to see what's going on? Any debug or tshooting info would be helpful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 18:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390347#M3220</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-10T18:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390701#M3223</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138634"&gt;@Eric.Hernandez&lt;/a&gt; ,  could you please send an email to 'fwmigrate@paloaltonetworks.com' and my team can schedule a live session to take a look at your issue. 

Thanks!</description>
      <pubDate>Thu, 11 Mar 2021 18:11:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390701#M3223</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2021-03-11T18:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390890#M3226</link>
      <description>&lt;P&gt;OK, will do. Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 14:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390890#M3226</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-12T14:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: APP-ID adoption doesn't output any app-IDs</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390962#M3232</link>
      <description>&lt;P&gt;Thank you so much for your help &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In summary, (in case anybody else runs into this issue), I first needed to send traffic logs from my devices into Panorama, as the app-id adoption makes a call to Panorama to gather the app-id statistics. Previously I only had my devices sending their traffic logs to Expedition. This worked fine for ML and RE. For APP-ID, the device traffic logs need to be in Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Secondly, Lynn was spot on when she suggested that the log connectors were probably the culprit. I have an Active/Passive pair, and the passive node has a lower serial number than the active node. In the LC, the devices are listed (top-down) based on serial number. The passive node was on top of the Active node (due to the lower serial number). It seems that the LC will check the first device in the list, and if there are no app-id stats, then it won't return anything. As soon as we only selected the active node, the APP-ID stats started working. This is the same with Active/Active devices (if one of the AA devices isn't passing traffic). The device passing traffic must be up top, otherwise you should only select the single device (the device passing traffic) within the LC.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 19:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/app-id-adoption-doesn-t-output-any-app-ids/m-p/390962#M3232</guid>
      <dc:creator>Eric.Hernandez</dc:creator>
      <dc:date>2021-03-12T19:20:47Z</dc:date>
    </item>
  </channel>
</rss>

