<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513981#M106721</link>
    <description>&lt;P&gt;Can someone please advise me on the above queries.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Sep 2022 03:55:26 GMT</pubDate>
    <dc:creator>RoneyRajan123</dc:creator>
    <dc:date>2022-09-06T03:55:26Z</dc:date>
    <item>
      <title>Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513962#M106716</link>
      <description>&lt;P&gt;Netflow is not working after upgrading to the 10.1.6-h6, is it something know issue in the 10.1.6-h6 PAN-OS version?&lt;/P&gt;
&lt;P&gt;Firewall- PA-3220&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have checked the NetFlow statics and seen that the firewall is sending the NetFlow log.&lt;/P&gt;
&lt;P&gt;for reference, I am also attaching the TCP dump snapshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone advice me please&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tcp.doc.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43672i750D1CA6D7A3BF7A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="tcp.doc.jpeg" alt="tcp.doc.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 18:11:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513962#M106716</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2022-09-05T18:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513981#M106721</link>
      <description>&lt;P&gt;Can someone please advise me on the above queries.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 03:55:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513981#M106721</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2022-09-06T03:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513999#M106722</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223437"&gt;@RoneyRajan123&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could not find any bug in release note that might have caused this. I had similar issue once before that was resolved by simply detaching NetFlow profile from interface, committing change and putting it back and committing again. Could you try this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 06:45:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/513999#M106722</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-06T06:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514007#M106724</link>
      <description>&lt;P&gt;Thank you for your response, Pavel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried it but there is no hope.&lt;/P&gt;
&lt;P&gt;In the firewall, I could able to see Netflow statistics.&lt;/P&gt;
&lt;P&gt;It is transmitting, however it is not receiving the Qradar server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue started&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-09-06 at 11.39.17 AM.jpeg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43678iEE98E3BC65A5CC38/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2022-09-06 at 11.39.17 AM.jpeg" alt="WhatsApp Image 2022-09-06 at 11.39.17 AM.jpeg" /&gt;&lt;/span&gt; after the firewall upgradation.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 08:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514007#M106724</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2022-09-06T08:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514099#M106735</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is there a way to do a pcap on the Qradar to see if its getting the packets? Perhaps something between the devices is blocking/dropping the traffic?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 19:14:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514099#M106735</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-06T19:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514108#M106737</link>
      <description>&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;said about verifying packet. If packets are being received at Qradar it may be that the Netflow source UniqueID sent by the PaloAlto may have changed when upgrading. Netflow receivers may use the source IP and/or the UniqueID (a 32bit unique source identifier) to match incoming packets to devices. You may have to re-associate the PaloAlto object in Qradar with its UniqueID.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 20:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514108#M106737</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-06T20:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514128#M106742</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;Thank you so much for your advices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will check it and update you from the Qradar side after performing the TCP dump.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meantime I have a question on the "Net flow Unique ID", as mentioned by the&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our case sender is the "PA" and receiver is the "Qradar", do I need to check the Unique ID on Qradar or our PA firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there is any way I can check this unique ID on PA firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because we only did changes on PA firewall (upgradation) after that only issue arised.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 06:38:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514128#M106742</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2022-09-07T06:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514159#M106753</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would just look on the Qradar and make sure the traffic is getting there. You shouldn't have to adjust the Unique ID.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 14:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514159#M106753</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-07T14:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514175#M106756</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The correction was there in between the firewall and Qradar, I have verified&lt;/P&gt;
&lt;P&gt;however the NetFlow log is not receiving at Qradar after upgradation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At firewall NetFlow logs is sending.&lt;/P&gt;
&lt;P&gt;can anyone advice me more troubleshooting step.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 17:40:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514175#M106756</guid>
      <dc:creator>RoneyRajan123</dc:creator>
      <dc:date>2022-09-07T17:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Netflow is not working after upgrade to the 10.1.6-h6, is it somthing know issue in 10.1.6-h6 PAN OS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514215#M106769</link>
      <description>&lt;P&gt;You say the firewall is sending Netflow traffic. Are the Netflow packets being sent from the switch port connected to the Qradar?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the packets are leaving the PaloAlto and being sent out the switch port connected to Qradar, then it seems like Qradar is not matching the incoming packets to the previous device profile. Sorry, I'm not familiar with exactly how Qradar is configured. But Netflow receivers generally have an "object" defined for the traffic source which is used to match inbound traffic to previously known devices. Can you try re-associating this object with the incoming packets?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The UniqueID sent by the PaloAlto is not something that can be changed. It is suppose to by a totally unique automatically created number in the Netflow source provider. That number may change it Netflow is sent from different interfaces or after major config changes - For instance, when I changed a bunch of Cisco routers to send Netflow from a management interface, instead of a routing interface, the UniqueID changed. I had to delete/recreate the source objects in Scrutinizer to match the new source IP/UniqueID pairing.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 00:07:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-is-not-working-after-upgrade-to-the-10-1-6-h6-is-it/m-p/514215#M106769</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-08T00:07:55Z</dc:date>
    </item>
  </channel>
</rss>

