<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RE error_SecRulesEnrich No traffic found in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/237925#M738</link>
    <description>&lt;P&gt;Maybe for that rule there is no log between the time period selected?&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 11:49:04 GMT</pubDate>
    <dc:creator>alestevez</dc:creator>
    <dc:date>2018-10-31T11:49:04Z</dc:date>
    <item>
      <title>RE error_SecRulesEnrich No traffic found</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/237602#M719</link>
      <description>&lt;P&gt;I have a problem with Rule Enrichment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error_SecRulesEnrich gives these messages after analysing the data from a rule which has a lot of data (at least by APP-ID):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Schermafbeelding 2018-10-29 om 15.36.56.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17352iF40AEE62B3C059B9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Schermafbeelding 2018-10-29 om 15.36.56.png" alt="Schermafbeelding 2018-10-29 om 15.36.56.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am connected to a firewall, and i can analyse in Expedition the applications (By APP-ID) and getting results.&lt;/P&gt;
&lt;P&gt;So i am confused why it sais, no traffic found.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MySQL is working, the "expedition internal checks" are all green.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Rule Enrichment is processing and results in "Completed"&lt;/P&gt;
&lt;P&gt;Also i rebooted the VM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 15:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/237602#M719</guid>
      <dc:creator>antono</dc:creator>
      <dc:date>2018-10-29T15:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: RE error_SecRulesEnrich No traffic found</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/237925#M738</link>
      <description>&lt;P&gt;Maybe for that rule there is no log between the time period selected?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 11:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/237925#M738</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-10-31T11:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: RE error_SecRulesEnrich No traffic found</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238175#M749</link>
      <description>&lt;P&gt;I changed the log collector time to several months. No change..&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 08:00:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238175#M749</guid>
      <dc:creator>antono</dc:creator>
      <dc:date>2018-11-01T08:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: RE error_SecRulesEnrich No traffic found</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238361#M754</link>
      <description>&lt;P&gt;Nobody who had this problem, found a solution?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 15:20:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238361#M754</guid>
      <dc:creator>antono</dc:creator>
      <dc:date>2018-11-02T15:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: RE error_SecRulesEnrich No traffic found</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238367#M755</link>
      <description>&lt;P&gt;Can you grep your csv file to see of there is any log entry for the rule name you are evaluating?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 15:57:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238367#M755</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-11-02T15:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: RE error_SecRulesEnrich No traffic found</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238567#M763</link>
      <description>&lt;P&gt;Eventually i found the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RL and ML does not read the logs directly from the Palo Alto logs, like APPID does.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After exporting an CSV file from the monitoring tab (filtered on the same rule as i want to analyse), and importing this CSV file to the local folder, and changing the security settings on this folder, i got it working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So for Rule Enrichment, there is a need of logging exported from the firewall&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2018 10:34:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/re-error-secrulesenrich-no-traffic-found/m-p/238567#M763</guid>
      <dc:creator>antono</dc:creator>
      <dc:date>2018-11-05T10:34:21Z</dc:date>
    </item>
  </channel>
</rss>

