<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check which IP address (or User, AD Group) is utilizing more bandwidth in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1118660#M122945</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149532229"&gt;@URONMAPU&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know Palo Alto Networks firewalls do not natively support email alerts triggered by bandwidth thresholds.&lt;/P&gt;
&lt;P&gt;However, you can achieve similar functionality through different methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/snmp-monitoring-and-traps" target="_blank" rel="noopener"&gt;SNMP monitoring&lt;/A&gt;&lt;/STRONG&gt; and external tools. You can configure the FW to send SNMP data to an external SIEM which in turn can alert you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similarly you can use netflow and have the Netflow collector server send you alerts (&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring&lt;/A&gt;&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also set up Log Forwarding to send log to an external system. Some of these logging servers have built in tools to send our reports/alerts (e.g. Splunk, ELK Stack, ...).&amp;nbsp; Alternatively you could develop a custom script to parse logs and monitor bandwidth usage and configure the script to send email alerts when thresholds are breached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly I can think of automation tools such as &lt;STRONG&gt;&lt;A href="https://www.paloaltonetworks.com/cortex/cortex-xsoar" target="_blank" rel="noopener"&gt;Cortex XSOAR&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;or similar third-party platforms like &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/incidents-and-alerts/alerts/create-a-notification-rule/integrate-with-servicenow" target="_blank" rel="noopener"&gt;ServiceNow&lt;/A&gt;&lt;/STRONG&gt; to monitor traffic logs and trigger email alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2025 08:59:41 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2025-01-20T08:59:41Z</dc:date>
    <item>
      <title>Check which IP address (or User, AD Group) is utilizing more bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1065866#M122853</link>
      <description>&lt;P&gt;Hi Bro,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to get a report on traffic usage via email with&amp;nbsp;a list of top users and their usage?&lt;/P&gt;
&lt;P&gt;I'm stuck on this problem. Hope someone can share with me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 10:18:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1065866#M122853</guid>
      <dc:creator>URONMAPU</dc:creator>
      <dc:date>2025-01-13T10:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Check which IP address (or User, AD Group) is utilizing more bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1065953#M122854</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149532229"&gt;@URONMAPU&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can schedule a report for email delivery.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/view-and-manage-reports/schedule-reports-for-email-delivery" target="_blank"&gt; https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/view-and-manage-reports/schedule-reports-for-email-delivery&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe the information found in the traffic report &amp;gt; sources is giving you the information you are looking for (source IP, username, bytes, sessions, etc,...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1736774449824.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65168i80C0AAC427676093/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1736774449824.png" alt="kiwi_0-1736774449824.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 13:22:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1065953#M122854</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-01-13T13:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Check which IP address (or User, AD Group) is utilizing more bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1066320#M122865</link>
      <description>&lt;P&gt;Hi Kim&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a way to schedule reports for daily delivery or delivered weekly on a specified day.&lt;BR /&gt;Our bandwidth is maxing out (for example 100MB) and I want to see who is using the most at that time.&lt;BR /&gt;I'm looking for a way to see a list of top usernames or IPs and their usage in this case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 02:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1066320#M122865</guid>
      <dc:creator>URONMAPU</dc:creator>
      <dc:date>2025-01-14T02:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Check which IP address (or User, AD Group) is utilizing more bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1066476#M122875</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149532229"&gt;@URONMAPU&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check the daily reports as shown in the screenshot under Monitor &amp;gt; Reports &amp;gt; Traffic Reports to see the high bandwith users for the past days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively you can check the ACC tab &amp;gt; Network Activity &amp;gt; User Activity.&amp;nbsp; Don't forget to select the desired timeframe or create a custom timeframe:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/acc" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/acc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another way is to go to the Networks tab &amp;gt; QoS and click on the 'Statistics' link on your QoS profile (if you have one):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-qos/qos-interface-statistics" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-qos/qos-interface-statistics&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 11:27:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1066476#M122875</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-01-14T11:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check which IP address (or User, AD Group) is utilizing more bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1066874#M122888</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a quick way to get a report on traffic usage via email?&lt;BR /&gt;When our bandwidth is maxing out (or 95%), I will receive an email notification from the system including a list of IPs (or top users) and their usage. No need to access to web interface and do a manually check.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 04:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1066874#M122888</guid>
      <dc:creator>URONMAPU</dc:creator>
      <dc:date>2025-01-15T04:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Check which IP address (or User, AD Group) is utilizing more bandwidth</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1118660#M122945</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/149532229"&gt;@URONMAPU&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know Palo Alto Networks firewalls do not natively support email alerts triggered by bandwidth thresholds.&lt;/P&gt;
&lt;P&gt;However, you can achieve similar functionality through different methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/snmp-monitoring-and-traps" target="_blank" rel="noopener"&gt;SNMP monitoring&lt;/A&gt;&lt;/STRONG&gt; and external tools. You can configure the FW to send SNMP data to an external SIEM which in turn can alert you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similarly you can use netflow and have the Netflow collector server send you alerts (&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/netflow-monitoring&lt;/A&gt;&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also set up Log Forwarding to send log to an external system. Some of these logging servers have built in tools to send our reports/alerts (e.g. Splunk, ELK Stack, ...).&amp;nbsp; Alternatively you could develop a custom script to parse logs and monitor bandwidth usage and configure the script to send email alerts when thresholds are breached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly I can think of automation tools such as &lt;STRONG&gt;&lt;A href="https://www.paloaltonetworks.com/cortex/cortex-xsoar" target="_blank" rel="noopener"&gt;Cortex XSOAR&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;or similar third-party platforms like &lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/incidents-and-alerts/alerts/create-a-notification-rule/integrate-with-servicenow" target="_blank" rel="noopener"&gt;ServiceNow&lt;/A&gt;&lt;/STRONG&gt; to monitor traffic logs and trigger email alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 08:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/check-which-ip-address-or-user-ad-group-is-utilizing-more/m-p/1118660#M122945</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-01-20T08:59:41Z</dc:date>
    </item>
  </channel>
</rss>

