<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server? in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/481966#M3959</link>
    <description>&lt;P&gt;Hi Roland,&lt;/P&gt;
&lt;P&gt;As I understand correctly you ended up doing a scheduled export from all panorama manged deviced to Expedition.&lt;/P&gt;
&lt;P&gt;I there no way to export the logs from panorama itself?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2022 13:46:53 GMT</pubDate>
    <dc:creator>zGomez</dc:creator>
    <dc:date>2022-04-22T13:46:53Z</dc:date>
    <item>
      <title>What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314379#M2362</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am working in an environment in which all Palo Alto FWs are centrally managed by a Panorama instance. All traffic logs are sent to the Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I follow the ML (Loggings Analysis) Guide, it is proposed to set a Scheduled Log Export from each individual FW towards the Expedition ML Server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But what is the correct approach in case we are using a centralized Panorama instance which is already receiving all these traffic logs? Should I still configure each individual firewall with an Scheduled Log Export towards the Expedition server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 14:49:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314379#M2362</guid>
      <dc:creator>roland_sterkendries</dc:creator>
      <dc:date>2020-03-04T14:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314409#M2363</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can import directly from Panorama in your situation.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 15:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314409#M2363</guid>
      <dc:creator>azuniga</dc:creator>
      <dc:date>2020-03-04T15:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314658#M2374</link>
      <description>&lt;P&gt;Hi Azuniga and thanks for answering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your proposition is actually what I did some days ago but it does not seem to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can schedule the export on the Panorama instance. The scp "ping" works fine copying a dummy file named &lt;STRONG&gt;ssh-export-test-txt&lt;/STRONG&gt;. However, later when the export should happen, it does not and the destination folder on the Expedition server remains empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Destination folder has following rights:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="expedition_rw_rights.png" style="width: 688px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24248i834F9DBAD34B2D4E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="expedition_rw_rights.png" alt="expedition_rw_rights.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seen this before? Could it be a bug?&lt;/P&gt;
&lt;P&gt;Thanks for any help/hint&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 10:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314658#M2374</guid>
      <dc:creator>roland_sterkendries</dc:creator>
      <dc:date>2020-03-05T10:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314741#M2377</link>
      <description>&lt;P&gt;I checked my file permissions on my personal VM and noticed I have permissions of 755, I am wondering if your file permissions were changed? I see that yours is 750 so it might not matter if the permissions are altered unless expedition writes to the file as other. Would you mind changing that and confirming your machine learning file path is set to /data, it should be under settings &amp;gt; m. learning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are still having issues please feel free to email us at fwmigrate (at) paloaltonetworks.com&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 17:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314741#M2377</guid>
      <dc:creator>azuniga</dc:creator>
      <dc:date>2020-03-05T17:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314746#M2378</link>
      <description>&lt;P&gt;If you can see that the&amp;nbsp;&lt;STRONG&gt;ssh-export-test-txt&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;test file gets generated in the /logs folder in your Expedition, this means that you have the settings in Expedition allowing the logs to be sent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, and you still do not get logs sent, it could be:&lt;/P&gt;
&lt;P&gt;a) did you commit the configuration in your FW to do the schedule log export?&lt;/P&gt;
&lt;P&gt;b) do you have traffic hitting rules in your firewall? (actually, I think you should get still traffic log files, but those would be empty in Expedition)&lt;/P&gt;
&lt;P&gt;c) are you actually seeing the traffic logs in the /logs folder? In such case, remember that you will be able to process the files in Expedition if you have imported the firewalls that own those traffic log files. Get into your Panorama device (in Expedition) and click on retrieve connected devices.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 17:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/314746#M2378</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-03-05T17:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/315747#M2410</link>
      <description>&lt;P&gt;Hi Dgildelaig,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could solve the issue this week. I will post it here for documentation. It turns out csv traffic logs cannot be exported from the Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;Even if you can configure a Scheduled Log Export centrally from the Panorama, this actually pushes the Scheduled Export to all FW devices and you still have to connect to all individual devices and click on their "SCP Test" button to exchange keys between FW-Expedition. This is because the exports are happening from the FWs and not from the Panorama.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 16:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/315747#M2410</guid>
      <dc:creator>roland_sterkendries</dc:creator>
      <dc:date>2020-03-11T16:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/315980#M2412</link>
      <description>&lt;P&gt;That's right.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An alternative is to use Expedition as a Syslog server and receive the traffic-logs on-realtime.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may find some information about how to setup Expedition to activate the syslog server features in this forum&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 09:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/315980#M2412</guid>
      <dc:creator>dgildelaig</dc:creator>
      <dc:date>2020-03-12T09:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: What is the correct way to export traffic logs from a Panorama to the ML Expedition Server?</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/481966#M3959</link>
      <description>&lt;P&gt;Hi Roland,&lt;/P&gt;
&lt;P&gt;As I understand correctly you ended up doing a scheduled export from all panorama manged deviced to Expedition.&lt;/P&gt;
&lt;P&gt;I there no way to export the logs from panorama itself?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 13:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/what-is-the-correct-way-to-export-traffic-logs-from-a-panorama/m-p/481966#M3959</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2022-04-22T13:46:53Z</dc:date>
    </item>
  </channel>
</rss>

