<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with ML with Logs Forward from Panorama in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529433#M4388</link>
    <description>&lt;P&gt;Thanks for the response, I am sure specifics are important, please see below the processed logs window, the device serial is underneath the window in black, not sure if its visible in the screenshot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisHammock_1-1675244074551.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47573i1F93D09D921E25AD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ChrisHammock_1-1675244074551.png" alt="ChrisHammock_1-1675244074551.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this matches what is in the csv logs in the PALogs folder header below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-01-26T16:21:36+00:00 RH-MGT-01.CustomerName.net 1,2023/01/26 16:21:36,012001053440,TRAFFIC,end,2305,2023/01/26 16:15:17&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if you need me to confirm settings anywhere else.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 09:35:37 GMT</pubDate>
    <dc:creator>ChrisHammock</dc:creator>
    <dc:date>2023-02-01T09:35:37Z</dc:date>
    <item>
      <title>Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529281#M4380</link>
      <description>&lt;P&gt;I am doing ML in Expedition for the first time.&amp;nbsp; The setup is, all FWs managed by single Panorama, logs forward from FWs to panorama.&amp;nbsp; I have setup panorama collector to forward the firewall logs to Expedition via syslog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have followed the online&amp;nbsp;"&lt;SPAN&gt;Log Analysis Features of Expedition" and am getting stuck at Module 9 Machine learning.&amp;nbsp; When I click the "Discovery" button -&amp;gt; Machine Learning.&amp;nbsp; The window pops up but the connectors just has a Loading... listed rather than the panorama or device serial number.&amp;nbsp; If I just ignore this and click analyze data it seems to quickly go to the completed stage with no information in the Learning results.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have tried Firefox and Chrome just in case this is a browser issue with basically the same results.&amp;nbsp; Obvioulsy the guide works on the basis of logs being sent direct from the firewall but I assume there is no reason I can't send the logs from panorama?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for any help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 11:04:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529281#M4380</guid>
      <dc:creator>ChrisHammock</dc:creator>
      <dc:date>2023-01-31T11:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529287#M4381</link>
      <description>&lt;P&gt;Additional information, below is a screenshot, note the connector status.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisHammock_0-1675165544605.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47551iFD3FAFBDACEFA04E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ChrisHammock_0-1675165544605.png" alt="ChrisHammock_0-1675165544605.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I have also attempted to use Rule Enrichment on the same rules, although the window does not contain a collector, when I click "Analyze Data" I still get completed with no results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could the issue be because the Device Group that contains the rules in panorama is not the same device group the firewalls are a member of, it is a parent of that device group.&amp;nbsp; I assume not as everything else in Expedition seems to understand this.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 11:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529287#M4381</guid>
      <dc:creator>ChrisHammock</dc:creator>
      <dc:date>2023-01-31T11:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529340#M4383</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160008"&gt;@ChrisHammock&lt;/a&gt;&amp;nbsp;For log connector, you will need to make sure the serial# of the firewall device you selected under panorama device group match the serial# of the firewall logs you had processed in the early steps. And when you enable the ML , you will need to enable it on the device group where the policy located&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 17:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529340#M4383</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-01-31T17:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529433#M4388</link>
      <description>&lt;P&gt;Thanks for the response, I am sure specifics are important, please see below the processed logs window, the device serial is underneath the window in black, not sure if its visible in the screenshot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisHammock_1-1675244074551.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47573i1F93D09D921E25AD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ChrisHammock_1-1675244074551.png" alt="ChrisHammock_1-1675244074551.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this matches what is in the csv logs in the PALogs folder header below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-01-26T16:21:36+00:00 RH-MGT-01.CustomerName.net 1,2023/01/26 16:21:36,012001053440,TRAFFIC,end,2305,2023/01/26 16:15:17&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if you need me to confirm settings anywhere else.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 09:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529433#M4388</guid>
      <dc:creator>ChrisHammock</dc:creator>
      <dc:date>2023-02-01T09:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529456#M4390</link>
      <description>&lt;P&gt;Thought this might be of use also&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisHammock_0-1675255002482.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47575iEE158D59682BBC71/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ChrisHammock_0-1675255002482.png" alt="ChrisHammock_0-1675255002482.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 12:37:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529456#M4390</guid>
      <dc:creator>ChrisHammock</dc:creator>
      <dc:date>2023-02-01T12:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529507#M4391</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160008"&gt;@ChrisHammock&lt;/a&gt;&amp;nbsp;Yes, those seems to be correct setting,&amp;nbsp; you could try only select ITE-FW-01 in the log connector see if it makes any difference.&amp;nbsp; If it still not working , please send an email to &lt;A href="mailto:fwmigrate@paloaltonetworks.com" target="_blank"&gt;fwmigrate@paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 16:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529507#M4391</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-02-01T16:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ML with Logs Forward from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529513#M4392</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629"&gt;@lychiang&lt;/a&gt;&amp;nbsp;that seemed to be the problem, if I remove the passive device, the connectors windows still just says "Loading..." as per the screenshot but the anayze actually provides results.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 17:04:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issues-with-ml-with-logs-forward-from-panorama/m-p/529513#M4392</guid>
      <dc:creator>ChrisHammock</dc:creator>
      <dc:date>2023-02-01T17:04:56Z</dc:date>
    </item>
  </channel>
</rss>

