<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Check Which IP Address (or User, AD Group) is Utilizing More Bandwidth in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-check-which-ip-address-or-user-ad-group-is/ta-p/1204702</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;A id="link_2_2cde314615eeb3_3eb3e" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/td-p/1065866#M122945" target="_blank" rel="noopener"&gt;Check which IP address (or User, AD Group) is utilizing more bandwidth&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149532229"&gt;@URONMAPU&lt;/a&gt;&amp;nbsp;&lt;A id="link_2cde314707595b_3eb3e" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300749" target="_self" aria-label="View Profile of Kevin_Ncs"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;answered by&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943" target="_blank" rel="noopener"&gt;@kiwi&lt;/A&gt;&amp;nbsp; &amp;nbsp;Read on to see the response!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi Bro,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to get a report on traffic usage via email with&amp;nbsp;a list of top users and their usage?&lt;/P&gt;
&lt;P&gt;I'm stuck on this problem. Hope someone can share with me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can schedule a report for email delivery.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/view-and-manage-reports/schedule-reports-for-email-delivery" target="_blank" rel="noopener"&gt; https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/view-and-manage-reports/schedule-reports-for-email-delivery&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The information found in the traffic report &amp;gt; sources is giving you the information you are looking for (source IP, username, bytes, sessions, etc,...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1736774449824.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65168i80C0AAC427676093/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1736774449824.png" alt="kiwi_0-1736774449824.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;This is a way to schedule reports for daily delivery or delivered weekly on a specified day.&lt;BR /&gt;Our bandwidth is maxing out (for example 100MB) and I want to see who is using the most at that time.&lt;BR /&gt;I'm looking for a way to see a list of top usernames or IPs and their usage in this case.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;You can check the daily reports as shown in the screenshot under Monitor &amp;gt; Reports &amp;gt; Traffic Reports to see the high bandwidth users for the past days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively you can check the ACC tab &amp;gt; Network Activity &amp;gt; User Activity.&amp;nbsp; Don't forget to select the desired timeframe or create a custom timeframe:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/acc" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/acc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another way is to go to the Networks tab &amp;gt; QoS and click on the 'Statistics' link on your QoS profile (if you have one):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-qos/qos-interface-statistics" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-qos/qos-interface-statistics&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a quick way to get a report on traffic usage via email?&lt;BR /&gt;When our bandwidth is maxing out (or 95%), I will receive an email notification from the system including a list of IPs (or top users) and their usage. No need to access to web interface and do a manually check.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Networks firewalls do not natively support email alerts triggered by bandwidth thresholds.&lt;/P&gt;
&lt;P&gt;However, you can achieve similar functionality through different methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/snmp-monitoring-and-traps" target="_blank" rel="noopener"&gt;SNMP monitoring&lt;/A&gt;&lt;/STRONG&gt; and external tools. You can configure the FW to send SNMP data to an external SIEM which in turn can alert you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similarly you can use netflow and have the Netflow collector server send you alerts (&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring&lt;/A&gt;&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also set up Log Forwarding to send log to an external system. Some of these logging servers have built in tools to send our reports/alerts (e.g. Splunk, ELK Stack, ...).&amp;nbsp; Alternatively you could develop a custom script to parse logs and monitor bandwidth usage and configure the script to send email alerts when thresholds are breached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly I can think of automation tools such as &lt;STRONG&gt;&lt;A href="https://www.paloaltonetworks.com/cortex/cortex-xsoar" target="_blank" rel="noopener"&gt;Cortex XSOAR&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;or similar third-party platforms like &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/incidents-and-alerts/alerts/create-a-notification-rule/integrate-with-servicenow" target="_blank" rel="noopener"&gt;ServiceNow&lt;/A&gt;&lt;/STRONG&gt; to monitor traffic logs and trigger email alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tags: technical documentation, SNMP, reporting and logging, administration, log forwarding, integration, acc&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 21 Jan 2025 16:30:56 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2025-01-21T16:30:56Z</dc:date>
    <item>
      <title>Nominated Discussion: Check Which IP Address (or User, AD Group) is Utilizing More Bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-check-which-ip-address-or-user-ad-group-is/ta-p/1204702</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;A id="link_2_2cde314615eeb3_3eb3e" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/td-p/1065866#M122945" target="_blank" rel="noopener"&gt;Check which IP address (or User, AD Group) is utilizing more bandwidth&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149532229"&gt;@URONMAPU&lt;/a&gt;&amp;nbsp;&lt;A id="link_2cde314707595b_3eb3e" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300749" target="_self" aria-label="View Profile of Kevin_Ncs"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;answered by&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943" target="_blank" rel="noopener"&gt;@kiwi&lt;/A&gt;&amp;nbsp; &amp;nbsp;Read on to see the response!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi Bro,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to get a report on traffic usage via email with&amp;nbsp;a list of top users and their usage?&lt;/P&gt;
&lt;P&gt;I'm stuck on this problem. Hope someone can share with me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can schedule a report for email delivery.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/view-and-manage-reports/schedule-reports-for-email-delivery" target="_blank" rel="noopener"&gt; https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/view-and-manage-reports/schedule-reports-for-email-delivery&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The information found in the traffic report &amp;gt; sources is giving you the information you are looking for (source IP, username, bytes, sessions, etc,...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1736774449824.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65168i80C0AAC427676093/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1736774449824.png" alt="kiwi_0-1736774449824.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;This is a way to schedule reports for daily delivery or delivered weekly on a specified day.&lt;BR /&gt;Our bandwidth is maxing out (for example 100MB) and I want to see who is using the most at that time.&lt;BR /&gt;I'm looking for a way to see a list of top usernames or IPs and their usage in this case.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;You can check the daily reports as shown in the screenshot under Monitor &amp;gt; Reports &amp;gt; Traffic Reports to see the high bandwidth users for the past days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively you can check the ACC tab &amp;gt; Network Activity &amp;gt; User Activity.&amp;nbsp; Don't forget to select the desired timeframe or create a custom timeframe:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/acc" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/acc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another way is to go to the Networks tab &amp;gt; QoS and click on the 'Statistics' link on your QoS profile (if you have one):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-qos/qos-interface-statistics" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-qos/qos-interface-statistics&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a quick way to get a report on traffic usage via email?&lt;BR /&gt;When our bandwidth is maxing out (or 95%), I will receive an email notification from the system including a list of IPs (or top users) and their usage. No need to access to web interface and do a manually check.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Networks firewalls do not natively support email alerts triggered by bandwidth thresholds.&lt;/P&gt;
&lt;P&gt;However, you can achieve similar functionality through different methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/snmp-monitoring-and-traps" target="_blank" rel="noopener"&gt;SNMP monitoring&lt;/A&gt;&lt;/STRONG&gt; and external tools. You can configure the FW to send SNMP data to an external SIEM which in turn can alert you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similarly you can use netflow and have the Netflow collector server send you alerts (&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring&lt;/A&gt;&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also set up Log Forwarding to send log to an external system. Some of these logging servers have built in tools to send our reports/alerts (e.g. Splunk, ELK Stack, ...).&amp;nbsp; Alternatively you could develop a custom script to parse logs and monitor bandwidth usage and configure the script to send email alerts when thresholds are breached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly I can think of automation tools such as &lt;STRONG&gt;&lt;A href="https://www.paloaltonetworks.com/cortex/cortex-xsoar" target="_blank" rel="noopener"&gt;Cortex XSOAR&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;or similar third-party platforms like &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/incidents-and-alerts/alerts/create-a-notification-rule/integrate-with-servicenow" target="_blank" rel="noopener"&gt;ServiceNow&lt;/A&gt;&lt;/STRONG&gt; to monitor traffic logs and trigger email alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tags: technical documentation, SNMP, reporting and logging, administration, log forwarding, integration, acc&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Jan 2025 16:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-check-which-ip-address-or-user-ad-group-is/ta-p/1204702</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-01-21T16:30:56Z</dc:date>
    </item>
  </channel>
</rss>

