<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how can I get entire session table? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18350#M13382</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe that ACC would help in this effort. Has that provided more information?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Oct 2013 00:26:44 GMT</pubDate>
    <dc:creator>sspringer</dc:creator>
    <dc:date>2013-10-25T00:26:44Z</dc:date>
    <item>
      <title>how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18345#M13377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Working on the 5060 in 5.0.7, the active session count is around 60k+, in cli '&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;show session all' output will only return ~3000 sessions.&amp;nbsp;&amp;nbsp; API returns 9995 lines.&amp;nbsp; How can I get the entire session table?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The use case,&amp;nbsp; I will like to be able to take a snapshot of the firewall session table at a given specific moment; find out which vsys has the most active sessions, group by top 10 source / destination ip address / destination port per vsys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ernest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18345#M13377</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-10-23T17:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18346#M13378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3999"&gt;Can the Whole Session Log be Exported?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think taking this report for the sessions after logged (from traffic logs )will give you parallel information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 08:36:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18346#M13378</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-24T08:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18347#M13379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the problem that I can see using the traffic logs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;traffic log is only generated when the session is closed/ended, unless you change policy setting to log at session start.&amp;nbsp; But it is not recommended, and you can't change all the policy at the same time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ernest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 16:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18347#M13379</guid>
      <dc:creator>workarounds</dc:creator>
      <dc:date>2013-10-24T16:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18348#M13380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;start session is used especially for debugging.you can cofigure this for all policy at one time if you don't have any configured.&lt;/P&gt;&lt;P&gt;Just edit your config with a tool(even word can do)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;change&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&amp;lt;log-start&amp;gt;no&amp;lt;/log-start&amp;gt;&lt;BR /&gt;&amp;lt;log-end&amp;gt;yes&amp;lt;/log-end&amp;gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&lt;STRONG&gt;to&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&amp;lt;log-start&amp;gt;yes&amp;lt;/log-start&amp;gt;&lt;BR /&gt;&amp;lt;log-end&amp;gt;yes&amp;lt;/log-end&amp;gt;&lt;BR /&gt; &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;Then after you examine what you need for a day or 1 week, you will rollback to old config.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 17:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18348#M13380</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-24T17:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18349#M13381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking from an operational perspective, if the firewall session table count is higher than normal, how do you find out which vsys/protocol/source ip/destination ip/destination ports is causing the high session counts?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 00:12:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18349#M13381</guid>
      <dc:creator>workarounds</dc:creator>
      <dc:date>2013-10-25T00:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18350#M13382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe that ACC would help in this effort. Has that provided more information?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 00:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18350#M13382</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-10-25T00:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18351#M13383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could always use the "count yes" syntax of the CLI command show session all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By adding progressively more specific filters, you can narrow down the sessions you are looking for. For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show session all filter count yes&lt;/P&gt;&lt;P&gt;&amp;gt; show session all filter count yes from trust&lt;/P&gt;&lt;P&gt;&amp;gt; show session all filter count yes from trust application web-browsing&lt;/P&gt;&lt;P&gt;&amp;gt; show session all filter count yes from trust application web-browsing source 192.0.2.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... and so on. By getting the count for each filter, you can find what may be odd in favor of what you are looking for. With the filter, you may not be able to display more than 3000 entries or whatever is present, but the count should help narrow down what is causing the imbalance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg Wesson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 00:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18351#M13383</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-10-25T00:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18352#M13384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right,&amp;nbsp; I can use show session meter to determine which vsys has the high session counts and start drill down from that point.&amp;nbsp; But some vsys has 15k+ sessions.&amp;nbsp; By drilling down via cli to determine the cause of the high session count, that could take few minutes if lucky, else you may not able to find the problem.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 01:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18352#M13384</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-10-25T01:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: how can I get entire session table?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18353#M13385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Again, ACC only get the data after the sessions closed and needed to wait 15 mins for ACC to update the information.&amp;nbsp; I don't think I have 15 mins to wait for an answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 14:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-entire-session-table/m-p/18353#M13385</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-10-25T14:36:31Z</dc:date>
    </item>
  </channel>
</rss>

