<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expedition Unable to Import Logs from PA-1410 in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540819#M4572</link>
    <description>&lt;P&gt;The customer exported the running configuration and provided it to me and I uploaded it manually. Expedition took the files without issue and I was able to import the device configuration into the project.&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2023 20:26:40 GMT</pubDate>
    <dc:creator>DanaHawkins</dc:creator>
    <dc:date>2023-05-02T20:26:40Z</dc:date>
    <item>
      <title>Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540640#M4564</link>
      <description>&lt;P&gt;I have a customer that is deploying a brand new PA-1410. This site is a greenfield site so they want to build security policies as they bring devices online. They've recently provided me with an export of logs and I'm trying to get them imported into Expedition. I want to run ML against the logs to build a base policy set based on what's seen. Then also provided me a configuration export as well which I'm using as my base configuration in Expedition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No matter what I do I can't get the logs to show up for processing. I even went as far as reinstalling Expedition from scratch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone tell me if PanOS 11.0 is supported in Expedition yet?&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 18:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540640#M4564</guid>
      <dc:creator>DanaHawkins</dc:creator>
      <dc:date>2023-05-01T18:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540669#M4565</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136634"&gt;@DanaHawkins&lt;/a&gt;&amp;nbsp; Yes, PAN-OS 11.x should be supported, few things to check :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Make sure your expedition is upgraded to v1.2.59&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Review ML settings are properly defined , the ML address match the expedition IP, if you don't know what's the IP, you can type 127.0.0.1 and click "save", it will show you the correct ML IP. Make sure the /data are listed in connection parquet settings:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_103411089d44cealychiang_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_103411089d44cealychiang_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-05-01 at 1.46.31 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49880iE3AB777B897D5FC9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-05-01 at 1.46.31 PM.png" alt="Screenshot 2023-05-01 at 1.46.31 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;&lt;SPAN&gt;Review ML folder permission /data and /PALlogs&amp;nbsp; like below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-05-01 at 1.51.01 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49881iFD0589AC23420C87/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-05-01 at 1.51.01 PM.png" alt="Screenshot 2023-05-01 at 1.51.01 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;if the permissions are not correct , you will need to issue below commands:&lt;/P&gt;
&lt;P&gt;#sudo chown -R www-data:www-data /data /PALogs&lt;/P&gt;
&lt;P&gt;#sudo chmod -R 775 /data /PALogs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. Make sure you are processing the logs on the correct Firewall device , the traffic log contain the serial# of the device that needs to match the serial # of the the firewall&amp;nbsp;device&lt;/P&gt;
&lt;P&gt;5. When process the logs, you can review below error logs:&lt;/P&gt;
&lt;OL&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/home/userSpace/panReadOrders.log: Review the call with the params for the spark process.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/tmp/command.spark: Review the call to spark. It can be copied and executed by hand for troubleshooting purposes, output will be printed on the cli.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/tmp/command_actions.spark: Review the call to spark. It can be copied and executed by hand for troubleshooting purposes, output will be printed on /tmp/error_logCoCo.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;/tmp/error_logCoCo: File containing the output of the spark command.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 01 May 2023 20:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540669#M4565</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-05-01T20:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540673#M4566</link>
      <description>&lt;P&gt;Thanks for the info. I'm going to review the logs to see if I can find anything in there that might help. I created the firewall device with the same serial number as what's in the logs. The only thing I can think of is 1400 series isn't a choice when you create the device. I just chose VM-Series.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will let you know what I find.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 21:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540673#M4566</guid>
      <dc:creator>DanaHawkins</dc:creator>
      <dc:date>2023-05-01T21:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540676#M4567</link>
      <description>&lt;P&gt;I'm going to have the customer re-export the log files again.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Checking: PeriodicLogCollectorCompacter&lt;BR /&gt;Mon, 01 May 2023 14:19:05 -0700 Start Task&lt;BR /&gt;Checking CSV logs from device(s) 2670100XXXX&lt;BR /&gt;Checking ML server is alive&lt;BR /&gt;ML Server is alive&lt;BR /&gt;Collecting device(s) serial(s)&lt;BR /&gt;2670100XXXX added&lt;BR /&gt;devicesData&lt;BR /&gt;Array&lt;BR /&gt;(&lt;BR /&gt;[0] =&amp;gt; stdClass Object&lt;BR /&gt;(&lt;BR /&gt;[serial] =&amp;gt; 2670100XXXX&lt;BR /&gt;[afterProcess] =&amp;gt;&lt;BR /&gt;)&lt;/P&gt;
&lt;P&gt;)&lt;BR /&gt;serialsAndData&lt;BR /&gt;Array&lt;BR /&gt;(&lt;BR /&gt;[0] =&amp;gt; Array&lt;BR /&gt;(&lt;BR /&gt;[serial] =&amp;gt; 2670100XXXX&lt;BR /&gt;[path] =&amp;gt; /PALogs/firewall/*&lt;BR /&gt;)&lt;/P&gt;
&lt;P&gt;)&lt;BR /&gt;&lt;STRONG&gt;No supported new files to process&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Success: -1 Errors: No supported new files to process&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Mon, 01 May 2023 14:19:05 -0700 End Task&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 21:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540676#M4567</guid>
      <dc:creator>DanaHawkins</dc:creator>
      <dc:date>2023-05-01T21:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540802#M4568</link>
      <description>&lt;P&gt;I'm still running into the same issue as I stated above. I loaded expedition on a completely different system as well. Has there been a change in the log format from 10.X to 11.X?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;expedition@del-expedition01:/PALogs/firewall$ sudo tail -f /home/userSpace/panReadOrders.log&lt;/P&gt;
&lt;P&gt;)&lt;BR /&gt;No supported new files to process&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Success: -1 Errors: No supported new files to process&lt;/P&gt;
&lt;P&gt;Tue, 02 May 2023 12:02:47 -0700 End Task&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Tue, 02 May 2023 12:05:17 -0700 Start Task&lt;BR /&gt;Checking CSV logs from device(s) 267010XXXXX&lt;BR /&gt;Checking ML server is alive&lt;BR /&gt;ML Server is alive&lt;BR /&gt;Collecting device(s) serial(s)&lt;BR /&gt;267010XXXXX added&lt;BR /&gt;devicesData&lt;BR /&gt;Array&lt;BR /&gt;(&lt;BR /&gt;[0] =&amp;gt; stdClass Object&lt;BR /&gt;(&lt;BR /&gt;[serial] =&amp;gt; 267010XXXXX&lt;BR /&gt;[afterProcess] =&amp;gt;&lt;BR /&gt;)&lt;/P&gt;
&lt;P&gt;)&lt;BR /&gt;serialsAndData&lt;BR /&gt;Array&lt;BR /&gt;(&lt;BR /&gt;[0] =&amp;gt; Array&lt;BR /&gt;(&lt;BR /&gt;[serial] =&amp;gt; 267010XXXXX&lt;BR /&gt;[path] =&amp;gt; /PALogs/firewall/*&lt;BR /&gt;)&lt;/P&gt;
&lt;P&gt;)&lt;BR /&gt;No supported new files to process&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Success: -1 Errors: No supported new files to process&lt;/P&gt;
&lt;P&gt;Tue, 02 May 2023 12:05:17 -0700 End Task&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 19:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540802#M4568</guid>
      <dc:creator>DanaHawkins</dc:creator>
      <dc:date>2023-05-02T19:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540812#M4569</link>
      <description>&lt;P&gt;Hi Dana,&lt;/P&gt;
&lt;P&gt;I see the path is&amp;nbsp;&amp;nbsp;/PALogs/firewall/* , can you please make sure the traffic logs are directly saved in /PALogs folder without any subfolder , also make sure all traffic logs under /PALogs have same permissions and owned by &lt;A href="http://www.data" target="_blank"&gt;www-data&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 20:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540812#M4569</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-05-02T20:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540817#M4570</link>
      <description>&lt;P&gt;I moved the csv file as you mentioned above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanaHawkins_1-1683058769952.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49907i03240FC5DC3D7395/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DanaHawkins_1-1683058769952.png" alt="DanaHawkins_1-1683058769952.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I also updated the ML configuration as well.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanaHawkins_2-1683058860018.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49908i074F7321F67ADDD6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DanaHawkins_2-1683058860018.png" alt="DanaHawkins_2-1683058860018.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I pulled the serial number directly from the log to create the device in Expedition. Expedition itself doesn't have access to the device though as it sit on the customer's network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 20:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540817#M4570</guid>
      <dc:creator>DanaHawkins</dc:creator>
      <dc:date>2023-05-02T20:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540818#M4571</link>
      <description>&lt;P&gt;You will need direct connection from expedition to firewall to be able to retrieve running configuration&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 20:24:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540818#M4571</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-05-02T20:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Expedition Unable to Import Logs from PA-1410</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540819#M4572</link>
      <description>&lt;P&gt;The customer exported the running configuration and provided it to me and I uploaded it manually. Expedition took the files without issue and I was able to import the device configuration into the project.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 20:26:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/expedition-unable-to-import-logs-from-pa-1410/m-p/540819#M4572</guid>
      <dc:creator>DanaHawkins</dc:creator>
      <dc:date>2023-05-02T20:26:40Z</dc:date>
    </item>
  </channel>
</rss>

