<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network monitor shows huge traffic spike, but can't find traffic details in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/network-monitor-shows-huge-traffic-spike-but-can-t-find-traffic/m-p/557812#M1834</link>
    <description>&lt;P&gt;Hey folks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a situation today whereby one of my PA's was responding really slowly across IPSec tunnels and for Global protect clients - so once I could get onto it I started digging into the network monitor to see if I could find out if there was a link/network load issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found a huge spike in traffic in the period concerned - much, much more than normal - but when I tried to check the traffic logs for matching application type, I can;t find anything which would come even close&amp;nbsp; to matching this level of load&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darren_g_0-1694648084743.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53689i53071A5DFFA4C98F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="darren_g_0-1694648084743.png" alt="darren_g_0-1694648084743.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The above shows the spike from the traffic monitor - you can see the increase plainly - and it lists as ms-ds-smbv3 - but when I go looking for that app in the traffic logs - there's minimal amounts - and none of it is in the period indicated by the network traffic monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know where I can dig to try and find out where this traffic was from/to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 23:38:43 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2023-09-13T23:38:43Z</dc:date>
    <item>
      <title>Network monitor shows huge traffic spike, but can't find traffic details</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/network-monitor-shows-huge-traffic-spike-but-can-t-find-traffic/m-p/557812#M1834</link>
      <description>&lt;P&gt;Hey folks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a situation today whereby one of my PA's was responding really slowly across IPSec tunnels and for Global protect clients - so once I could get onto it I started digging into the network monitor to see if I could find out if there was a link/network load issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found a huge spike in traffic in the period concerned - much, much more than normal - but when I tried to check the traffic logs for matching application type, I can;t find anything which would come even close&amp;nbsp; to matching this level of load&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darren_g_0-1694648084743.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53689i53071A5DFFA4C98F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="darren_g_0-1694648084743.png" alt="darren_g_0-1694648084743.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The above shows the spike from the traffic monitor - you can see the increase plainly - and it lists as ms-ds-smbv3 - but when I go looking for that app in the traffic logs - there's minimal amounts - and none of it is in the period indicated by the network traffic monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know where I can dig to try and find out where this traffic was from/to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 23:38:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/network-monitor-shows-huge-traffic-spike-but-can-t-find-traffic/m-p/557812#M1834</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2023-09-13T23:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Network monitor shows huge traffic spike, but can't find traffic details</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/network-monitor-shows-huge-traffic-spike-but-can-t-find-traffic/m-p/558379#M1864</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Note that traffic log will be generated at the session end (by default) so if you filter your logs with timeframe you will be looking at the timeframe when the log was created. You may need to filter based on session start - which is available field in the log entry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also look at the amount of total bytes (column that summarize the sent and receive). You may also&amp;nbsp; try to apply filter to should only logs for SMB app that has total bytes greater than X&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 13:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/network-monitor-shows-huge-traffic-spike-but-can-t-find-traffic/m-p/558379#M1864</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T13:58:17Z</dc:date>
    </item>
  </channel>
</rss>

