<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: M.Learning Analysis results empty in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584910#M5031</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125412"&gt;@chris.weakland&lt;/a&gt;&amp;nbsp;I guess your issue is related to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/273906"&gt;@sanandh&lt;/a&gt;&amp;nbsp;mentions regarding the FW serials matching. So besides his comments, please do below:&lt;/P&gt;
&lt;P&gt;1) Edit your Panorama and set it up as "vm-panorama".&lt;/P&gt;
&lt;P&gt;2) Open your project again, go to plugins and create a new log connector, in this case you should be able to select the device, the source file and the DG but also selecting the FWs. See attached screenshot for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dpuigdomenec_0-1714035781709.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59304i8EBB41562832816D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dpuigdomenec_0-1714035781709.png" alt="dpuigdomenec_0-1714035781709.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Apr 2024 09:05:11 GMT</pubDate>
    <dc:creator>dpuigdomenec</dc:creator>
    <dc:date>2024-04-25T09:05:11Z</dc:date>
    <item>
      <title>M.Learning Analysis results empty</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584836#M5029</link>
      <description>&lt;P&gt;Currently I have a Panorama managed firewall, I have added Panorama to Expedition (Running v1.2.86), and I am sending syslogs from the firewall to Expedition. Logs are showing up and are being processed:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrisweakland_0-1713991396913.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59269i15BAA34F0EF1E711/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrisweakland_0-1713991396913.png" alt="chrisweakland_0-1713991396913.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrisweakland_1-1713991719571.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59271i8FEE0CDC6D4795CB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrisweakland_1-1713991719571.png" alt="chrisweakland_1-1713991719571.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a project created, Panorama configuration imported, I can see the ruleset for the firewall in question. I have the log connector set to Panorama and the device group for the firewall selected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrisweakland_2-1713991845736.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59272i5C5E57E6EC7560B1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrisweakland_2-1713991845736.png" alt="chrisweakland_2-1713991845736.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the policy, I have enabled ML on the rules I am interested in. However, when I run the analysis, I get an empty result:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrisweakland_3-1713991913002.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59273i3B85858375E8F1B2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrisweakland_3-1713991913002.png" alt="chrisweakland_3-1713991913002.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrisweakland_0-1713993251600.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59275iEDF1CA8778DC817F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chrisweakland_0-1713993251600.png" alt="chrisweakland_0-1713993251600.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone chime in on how to resolve this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 21:14:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584836#M5029</guid>
      <dc:creator>chris.weakland</dc:creator>
      <dc:date>2024-04-24T21:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: M.Learning Analysis results empty</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584851#M5030</link>
      <description>&lt;P&gt;There are couple of things to double check:&lt;BR /&gt;- Verify the logs have the serial number matching the serial used to initiate the ML analysis. In case of HA pairs, the logs could be using a different serial.&lt;/P&gt;
&lt;P&gt;- Verify there are logs for the rule you are analyzing . If there are no matching logs, the analysis result will be empty&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 22:33:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584851#M5030</guid>
      <dc:creator>sanandh</dc:creator>
      <dc:date>2024-04-24T22:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: M.Learning Analysis results empty</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584910#M5031</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125412"&gt;@chris.weakland&lt;/a&gt;&amp;nbsp;I guess your issue is related to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/273906"&gt;@sanandh&lt;/a&gt;&amp;nbsp;mentions regarding the FW serials matching. So besides his comments, please do below:&lt;/P&gt;
&lt;P&gt;1) Edit your Panorama and set it up as "vm-panorama".&lt;/P&gt;
&lt;P&gt;2) Open your project again, go to plugins and create a new log connector, in this case you should be able to select the device, the source file and the DG but also selecting the FWs. See attached screenshot for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dpuigdomenec_0-1714035781709.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59304i8EBB41562832816D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dpuigdomenec_0-1714035781709.png" alt="dpuigdomenec_0-1714035781709.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 09:05:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584910#M5031</guid>
      <dc:creator>dpuigdomenec</dc:creator>
      <dc:date>2024-04-25T09:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: M.Learning Analysis results empty</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584929#M5032</link>
      <description>&lt;P&gt;Thank you David, that did the trick!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 13:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/m-learning-analysis-results-empty/m-p/584929#M5032</guid>
      <dc:creator>chris.weakland</dc:creator>
      <dc:date>2024-04-25T13:38:47Z</dc:date>
    </item>
  </channel>
</rss>

