<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama log import in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/431777#M3568</link>
    <description>&lt;P&gt;I noticed when I went to the Devices tab, double clicked my Panorama, then went to the Panorama Devices tab and clicked Retrieve Connected Devices, when that finishes, the logs all now show for a different firewall so still not correct, but changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 05 Sep 2021 18:20:21 GMT</pubDate>
    <dc:creator>Alex_Kalbfell</dc:creator>
    <dc:date>2021-09-05T18:20:21Z</dc:date>
    <item>
      <title>Panorama log import</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/431689#M3566</link>
      <description>&lt;P&gt;I have firewalls managed by Panorama that I want to do some ML and RE on traffic logs. Right now I have this setup for 2 firewalls using the log export feature on the firewalls. Each firewall exports traffic logs to a different folder on my Expedition server. In Expedition I have added my Panorama and from the devices tab, I show all devices to see the firewalls managed by Panorama. Within the firewalls, I have setup the appropriate folder on the M. Learning tab and all of that works as expected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is when I go to the Panorama object under Devices and click on the M. Learning tab, I see all the logs from the 2 firewalls but under the "Device" column, it shows a totally different firewall that has nothing to do with this other than the fact it's also managed by Panorama. When I try to do any ML or RE for the firewalls that are sending logs, it fails, I assume because Panorama thinks those logs are for the other firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone seen this before or know how to fix it?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Sep 2021 00:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/431689#M3566</guid>
      <dc:creator>Alex_Kalbfell</dc:creator>
      <dc:date>2021-09-05T00:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama log import</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/431777#M3568</link>
      <description>&lt;P&gt;I noticed when I went to the Devices tab, double clicked my Panorama, then went to the Panorama Devices tab and clicked Retrieve Connected Devices, when that finishes, the logs all now show for a different firewall so still not correct, but changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Sep 2021 18:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/431777#M3568</guid>
      <dc:creator>Alex_Kalbfell</dc:creator>
      <dc:date>2021-09-05T18:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama log import</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/432308#M3572</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155135"&gt;@Alex_Kalbfell&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is kinda hard to understand the issue here, but usually the serial number is the separate firewall identifier we use to isolate the log files. Can you provide screenshots of what you are saying? If you're unable to do that please email us at &lt;A href="mailto:fwmigrate@paloaltonetworks.com" target="_blank"&gt;fwmigrate@paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please include your version of expedition I know we had some problems with ML on 1.1.104 so if you're running that version of expedition please upgrade to the latest version.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 15:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/432308#M3572</guid>
      <dc:creator>azuniga</dc:creator>
      <dc:date>2021-09-07T15:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama log import</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/433097#M3577</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132922"&gt;@azuniga&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for replying and my apologies if the original posts were confusing. I did reach out to that email address over the weekend and am waiting to hear back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully this is a better explanation of the issue...&lt;/P&gt;
&lt;P&gt;The firewalls are set to export traffic logs to the expedition server which works fine. Before Expedition processes the logs, if I look at the ML.Learning tab for Panorama, I see the logs there and the device column matches up to the correct device, but when the logs get processed, the device name changes to a totally different firewall. If I try to run ML or RE on any of the firewalls that have had logs processed, it just sits on initializing forever so it seems as if because after processing of logs, the logs are "assigned" to a different firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached are a couple of screenshots although I had to scrub out full names. One shows a log file for a firewall with DC-MDF1-FW01 in the name and the device column is correct. This is before that log file is processed. The next screenshot shows after processing and you can see that the device column now shows a totally different firewall.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-09-10 at 10.16.39 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36310i805E82083C348522/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-09-10 at 10.16.39 AM.png" alt="Screen Shot 2021-09-10 at 10.16.39 AM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-09-05 at 10.19.05 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36311i05F73D11D776FF43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-09-05 at 10.19.05 PM.png" alt="Screen Shot 2021-09-05 at 10.19.05 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 14:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/433097#M3577</guid>
      <dc:creator>Alex_Kalbfell</dc:creator>
      <dc:date>2021-09-10T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama log import</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/433121#M3579</link>
      <description>&lt;P&gt;Instead of going Devices&amp;gt;Panorama&amp;gt;M.Learning , go Devices&amp;gt;Panorama&amp;gt;&lt;EM&gt;expand list&lt;/EM&gt;&amp;gt;[FW in question]&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenKnorr2_0-1631287056017.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36315i7F4EF73F8696D0D9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenKnorr2_0-1631287056017.png" alt="BenKnorr2_0-1631287056017.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Not sure if you're doing this already but your screenshots show Panorama instead of FWs themselves. I'm not sure how the GUI is supposed to work where Panorama is managing firewalls in this regard, but in my experience with ML and Panorama, I go this route to configure the log ingestion processing for ML on each FW. Config for rules comes via syncing it from Devices&amp;gt;Panorama as normal.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 15:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/433121#M3579</guid>
      <dc:creator>BenKnorr2</dc:creator>
      <dc:date>2021-09-10T15:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama log import</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/435522#M3596</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114413"&gt;@BenKnorr2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks. I have it configured for each device like that. I think the issue I am running into is the right way to get Panorama, the firewall and expedition to all work together. If I try this on a firewall not connected to Panorama, I have no issues.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 13:53:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/panorama-log-import/m-p/435522#M3596</guid>
      <dc:creator>Alex_Kalbfell</dc:creator>
      <dc:date>2021-09-21T13:53:36Z</dc:date>
    </item>
  </channel>
</rss>

