<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule enrichment help in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521326#M4258</link>
    <description>&lt;P&gt;You might want to delete the device and re-add the firewall, retrieve the running config again.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Nov 2022 21:24:48 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2022-11-15T21:24:48Z</dc:date>
    <item>
      <title>Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521177#M4252</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is my first time attempting rule-enrichment on expedition.&amp;nbsp; I followed the LIVEcommunity youtube videos for instructions. Logs exporting from the firewall for the last 90 days, and have already processed the logs. I have now enabled RE monitoring on a security policy, and when I got to RE discovery, the analyze data button brings up a log connector window. I can select the device here, but nothing else. Could somebody please let me know what steps I'm missing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This first time I tried it, there was an xml file on the source dropdown, but it is no longer an option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_3-1668443506073.png" style="width: 986px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45324i88DA6592C8B7D9F0/image-dimensions/986x328/is-moderation-mode/true?v=v2" width="986" height="328" role="button" title="JoshuaNezat_3-1668443506073.png" alt="JoshuaNezat_3-1668443506073.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_2-1668443431817.png" style="width: 692px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45323i117B53984F9BAEC9/image-dimensions/692x472/is-moderation-mode/true?v=v2" width="692" height="472" role="button" title="JoshuaNezat_2-1668443431817.png" alt="JoshuaNezat_2-1668443431817.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_1-1668443300252.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45322i5C9551AFB4A8987D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JoshuaNezat_1-1668443300252.png" alt="JoshuaNezat_1-1668443300252.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_0-1668443247073.png" style="width: 690px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45321iE5FFF34E2B6844CA/image-dimensions/690x516/is-moderation-mode/true?v=v2" width="690" height="516" role="button" title="JoshuaNezat_0-1668443247073.png" alt="JoshuaNezat_0-1668443247073.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 16:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521177#M4252</guid>
      <dc:creator>Joshua-Nezat</dc:creator>
      <dc:date>2022-11-14T16:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521180#M4253</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176215"&gt;@Joshua-Nezat&lt;/a&gt;&amp;nbsp;If your config is panorama config, you will add panorama device in the device tab and click "show all device " on the top right corner. find the firewalls that have logs, and process the logs there. Then you will need to select panorama device and select the specific device group that contain the firewalls that you have processed the logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 16:42:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521180#M4253</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-11-14T16:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521184#M4254</link>
      <description>&lt;P&gt;Thanks for your recommendation, but I do not have a panorama in this deployment. These firewalls are managed locally. Does that change anything?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 17:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521184#M4254</guid>
      <dc:creator>Joshua-Nezat</dc:creator>
      <dc:date>2022-11-14T17:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521189#M4255</link>
      <description>&lt;P&gt;If your config is in firewall, you can use firewall as log connector, just select the firewall device and the config in the source, vsys1 in virtual system field, assume this is a single vsys firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 17:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521189#M4255</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-11-14T17:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521196#M4256</link>
      <description>&lt;P&gt;Okay I think I understand. The problem is, I am not able to select the firewall device config in the source field. The source drop-down menu (circled in blue below) gives me no options to select.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_0-1668454843505.png" style="width: 946px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45328i17B78906D59A2DF3/image-dimensions/946x551/is-moderation-mode/true?v=v2" width="946" height="551" role="button" title="JoshuaNezat_0-1668454843505.png" alt="JoshuaNezat_0-1668454843505.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 19:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521196#M4256</guid>
      <dc:creator>Joshua-Nezat</dc:creator>
      <dc:date>2022-11-14T19:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521203#M4257</link>
      <description>&lt;P&gt;So I deleted the project, rebooted expedition, created new project, reimported device config, selected policy for rule enrichment monitoring, and now I have an option for the source.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_0-1668458321191.png" style="width: 464px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45330i38A1A73E58E035C9/image-dimensions/464x370/is-moderation-mode/true?v=v2" width="464" height="370" role="button" title="JoshuaNezat_0-1668458321191.png" alt="JoshuaNezat_0-1668458321191.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After clicking save, it takes me back to the rule enrichment window, but nothing has changed. It still says "no devices in the logConnector" at the bottom of the window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshuaNezat_1-1668458491708.png" style="width: 1256px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45331iC181C757A680495B/image-dimensions/1256x647/is-moderation-mode/true?v=v2" width="1256" height="647" role="button" title="JoshuaNezat_1-1668458491708.png" alt="JoshuaNezat_1-1668458491708.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 20:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521203#M4257</guid>
      <dc:creator>Joshua-Nezat</dc:creator>
      <dc:date>2022-11-14T20:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Rule enrichment help</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521326#M4258</link>
      <description>&lt;P&gt;You might want to delete the device and re-add the firewall, retrieve the running config again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 21:24:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/rule-enrichment-help/m-p/521326#M4258</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-11-15T21:24:48Z</dc:date>
    </item>
  </channel>
</rss>

