<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The '/PALogs/&amp;lt;firewall logs folder&amp;gt;' cannot be scanned. ' in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/417526#M3414</link>
    <description>&lt;P&gt;Verify there are no permission issues with the folder and the owner is www-data:expedition you could always change the folder permissions to chmod 777 /PALogs to see if that helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jul 2021 14:47:59 GMT</pubDate>
    <dc:creator>azuniga</dc:creator>
    <dc:date>2021-07-07T14:47:59Z</dc:date>
    <item>
      <title>The '/PALogs/&lt;firewall logs folder&gt;' cannot be scanned. '</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/417482#M3413</link>
      <description>&lt;P&gt;I am getting the following error when trying to scan my log folder on expedition "The '/PALogs/&amp;lt;firewall logs folder&amp;gt;' cannot be scanned. '."&amp;nbsp; I am on version 1.1.101. I also am wondering if maybe my rsylog configuration is not right. The folders being created are created by root.&amp;nbsp; I have no issues if I import files manually.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 13:02:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/417482#M3413</guid>
      <dc:creator>patrick.blumer</dc:creator>
      <dc:date>2021-07-07T13:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: The '/PALogs/&lt;firewall logs folder&gt;' cannot be scanned. '</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/417526#M3414</link>
      <description>&lt;P&gt;Verify there are no permission issues with the folder and the owner is www-data:expedition you could always change the folder permissions to chmod 777 /PALogs to see if that helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 14:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/417526#M3414</guid>
      <dc:creator>azuniga</dc:creator>
      <dc:date>2021-07-07T14:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: The '/PALogs/&lt;firewall logs folder&gt;' cannot be scanned. '</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/577524#M4946</link>
      <description>&lt;P&gt;did you find any solution on this?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 15:33:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/577524#M4946</guid>
      <dc:creator>Vinayak1</dc:creator>
      <dc:date>2024-02-16T15:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: The '/PALogs/&lt;firewall logs folder&gt;' cannot be scanned. '</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/577913#M4949</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/330641"&gt;@Vinayak1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have some issues while trying to analyse your logs please follow below troubleshooting steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) (If logs does not appear in Expedition) Check NGFW and Expedition has communication. Open the NGFW terminal and execute:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;ssh host &lt;A href="mailto:expedition@$VM_EXPEDITION" target="_blank"&gt;expedition@$VM_EXPEDITION&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2) Check the /PALogs/ and the /data/ folders has the correct grants&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;chown -R www-data:www-data /data&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;chown -R www-data:www-data /PALogs/&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) Review in the UI settings that ML settings are correct.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4)&amp;nbsp;Define your device. Make sure the serial number is the one reported on FW logs. Also set the device as a NGFW. &lt;STRONG&gt;Panorama devices can not proceed logs&lt;/STRONG&gt;.&amp;nbsp;NOTE: Expedition gets the 3rd line of the log file to get the mapping between the device and the log file.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Make sure java is installed. Execute: java -version or&amp;nbsp;apt list --installed | grep jdk .&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;If it is not installed execute: apt-get install -y openjdk-8-jre-headless&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Process the logs (&lt;/SPAN&gt;&lt;STRONG&gt;Panorama devices can not proceed logs&lt;/STRONG&gt;&lt;SPAN&gt;) manually. Execute the action in below order:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Define /PALogs/&lt;/SPAN&gt;&lt;STRONG&gt;$folderORFileName&lt;/STRONG&gt;&lt;SPAN&gt;* as the folder where FW logs are stored. Make sure www-data has granted permission.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Click on Save&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Enter again into the device and select tab ML&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Click on Process Enabled Files&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Wait until the process is finished. Meanwhile review below logs.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/home/userSpace/panReadOrders.log: Review the call with the params for the spark process.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/tmp/command.spark: Review the call to spark. It can be copied and executed by hand for troubleshooting purposes, output will be printed on the cli.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/tmp/command_actions.spark: Review the call to spark. It can be copied and executed by hand for troubleshooting purposes, output will be printed on /tmp/error_logCoCo.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/tmp/error_logCoCo: File containing the output of the spark command.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;During the execution of the analysis you will see also the creation of a couple of csv files; *_afterProcess.csv (actions to perform after the logs are processed), *_traffic_files.csv (listing of the processed files)&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;Let me know if you have any other question,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;David&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 15:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/the-palogs-lt-firewall-logs-folder-gt-cannot-be-scanned/m-p/577913#M4949</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2024-02-21T15:08:11Z</dc:date>
    </item>
  </channel>
</rss>

