<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NetFlow not Working with Qradar in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-not-working-with-qradar/m-p/547932#M111894</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I found the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the HA to remain synchronize, we need to set the service route manually on both platforms (active and passive) to be the same interface data (PA 52xx and PA 7xxx).&lt;/P&gt;
&lt;P&gt;Once you complete&amp;nbsp; your netflow configuration on the active PA and you commit, the cluster (HA) will synchronize correctly.&lt;/P&gt;
&lt;P&gt;Thanks;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jul 2023 02:51:32 GMT</pubDate>
    <dc:creator>Nathus</dc:creator>
    <dc:date>2023-07-02T02:51:32Z</dc:date>
    <item>
      <title>NetFlow not Working with Qradar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-not-working-with-qradar/m-p/547860#M111888</link>
      <description>&lt;P&gt;Hello !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im having issue with my netflow configuration on the PA5260 in HA mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not receiving any log on my Qradar where as i have configure the netflow by following the&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJzCAK" target="_blank" rel="nofollow noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJzCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The following Step have beeen done:&lt;/P&gt;
&lt;P&gt;1. Netflow profil created&lt;/P&gt;
&lt;P&gt;2. Profil applied on a subinterface&lt;/P&gt;
&lt;P&gt;3. use of ae3 interface in a service route.&lt;/P&gt;
&lt;P&gt;4. connectivite between ae3 interface and the Qradar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And my HA peer is not synchronize also even i try manuel config sync&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The configuration is like something in below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show | match netflow&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set deviceconfig system route service netflow source address 10.10.10.14/29&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set deviceconfig system route service netflow source interface ae3.600&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set network interface tunnel units tunnel.11 netflow-profile NetFlow_SOC_Qradar&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set network interface tunnel units tunnel.14 netflow-profile NetFlow_SOC_Qradar&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared server-profile netflow NetFlow_SOC_Qradar server Qradar host 1.1.1.1/24&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared server-profile netflow NetFlow_SOC_Qradar server Qradar port 2055&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared server-profile netflow NetFlow_SOC_Qradar template-refresh-rate minutes 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared server-profile netflow NetFlow_SOC_Qradar template-refresh-rate packets 20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared server-profile netflow NetFlow_SOC_Qradar active-timeout 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared server-profile netflow NetFlow_SOC_Qradar export-enterprise-fields no&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set shared admin-role Monitor-full-access role device webui device server-profile netflow read-only&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thansk in advance for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 09:55:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-not-working-with-qradar/m-p/547860#M111888</guid>
      <dc:creator>Nathus</dc:creator>
      <dc:date>2023-06-30T09:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: NetFlow not Working with Qradar</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/netflow-not-working-with-qradar/m-p/547932#M111894</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I found the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the HA to remain synchronize, we need to set the service route manually on both platforms (active and passive) to be the same interface data (PA 52xx and PA 7xxx).&lt;/P&gt;
&lt;P&gt;Once you complete&amp;nbsp; your netflow configuration on the active PA and you commit, the cluster (HA) will synchronize correctly.&lt;/P&gt;
&lt;P&gt;Thanks;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jul 2023 02:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/netflow-not-working-with-qradar/m-p/547932#M111894</guid>
      <dc:creator>Nathus</dc:creator>
      <dc:date>2023-07-02T02:51:32Z</dc:date>
    </item>
  </channel>
</rss>

