<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Lot of 'insufficient-data' in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31943#M23391</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We see a lot of 'insufficient-data' traffic on our firewall and we couldn't find any reason so far. Does anyone have a good idea on how we can troubleshoot the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we click on the insufficient-data bar we get redirected to the ACC but it doesn't show much there...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Insufficient-data.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3282_Insufficient-data.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Insufficient-data2.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3283_Insufficient-data2.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jul 2012 22:38:25 GMT</pubDate>
    <dc:creator>oschuler</dc:creator>
    <dc:date>2012-07-13T22:38:25Z</dc:date>
    <item>
      <title>Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31943#M23391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We see a lot of 'insufficient-data' traffic on our firewall and we couldn't find any reason so far. Does anyone have a good idea on how we can troubleshoot the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we click on the insufficient-data bar we get redirected to the ACC but it doesn't show much there...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Insufficient-data.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3282_Insufficient-data.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Insufficient-data2.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3283_Insufficient-data2.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 22:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31943#M23391</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-13T22:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31944#M23392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt;Insufficient data in the application field usually means&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt; that there was not enough data to identify the application. For example, if the 3-way TCP handshake was completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, you would see insufficient data in the application field of the traffic log.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt;You can try to filter the traffic logs based on the application filter set to '&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt;Insufficient data' and see what traffic it is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt;You can refer to this doc:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'Times New Roman','serif';"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;Incomplete, Insufficient data and Not-applicable in the application field&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jul 2012 00:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31944#M23392</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2012-07-14T00:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31945#M23393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. We tried that already. When we filter for 'insufficient-data' for the time frame above (18:30 - 00:30) we get a result set of only 41 rows. Each row reports only ~900 bytes up to 1.5 KB of data. If we sum that up, we get a maximum of 60 KB of insufficient data for these 6 hours. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look at the amount of insufficient-data in the first picture, you see that there are more than 2 GB of insufficient data in the mentioned time frame...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jul 2012 13:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31945#M23393</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-14T13:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31946#M23394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As much as I hate to say it, the "insufficient data" is showing up because part of the traffic is being dropped, and thus it is unable to determine what app is really being used.&lt;/P&gt;&lt;P&gt;Sometimes creating an "open" rule to allow the traffic, monitoring for that traffic, properly identifying the traffic, and then allow the traffic being specific helps.&lt;/P&gt;&lt;P&gt;This is because we do not look at the TCP handshake to determine what app is being used.. so that might work, but not the true "data", thus it shows up as Insuffient data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 20:26:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31946#M23394</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-07-19T20:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31947#M23395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, so that means we'd have to set our last rule (Deny and log everything else) to "allow"? Sounds not like a charming solution, hehe :smileygrin:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2012 12:16:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31947#M23395</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-23T12:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31948#M23396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is only recommended to do that for a short period of time. Sort of a Discovery of the network.&amp;nbsp; Then you can narrow down the rule to just what you want/need.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 12:30:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31948#M23396</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-07-24T12:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Lot of 'insufficient-data'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31949#M23397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, we'll try that the next weekend. I'll post the result here next week. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 18:35:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lot-of-insufficient-data/m-p/31949#M23397</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-24T18:35:53Z</dc:date>
    </item>
  </channel>
</rss>

