<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unknown Application Packet Capture in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34795#M25543</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following doc explains about unknow apps&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2007"&gt;https://live.paloaltonetworks.com/docs/DOC-2007&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also following document explains how to request an new application&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1879"&gt;https://live.paloaltonetworks.com/docs/DOC-1879&lt;/A&gt;&lt;/P&gt;&lt;P&gt;you can also create an app override for an application that is internal to your network and you know the port numbers&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;https://live.paloaltonetworks.com/docs/DOC-1071&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Following doc explains what application override does&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1343"&gt;https://live.paloaltonetworks.com/docs/DOC-1343&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Aug 2013 05:37:53 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2013-08-06T05:37:53Z</dc:date>
    <item>
      <title>Unknown Application Packet Capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34793#M25541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want know about Unknown packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q1. Where is unknown pcap stored?&lt;/P&gt;&lt;P&gt; [Device] &amp;gt; [Setup] &amp;gt; [Management] &amp;gt; [ Logging and Reporting Settings]&lt;/P&gt;&lt;P&gt; App Pkt Capture ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2. I want know Unknown Pcap Usage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q3. When is capture unknown packet in PA packet flow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 06:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34793#M25541</guid>
      <dc:creator>smaekawa</dc:creator>
      <dc:date>2013-08-05T06:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown Application Packet Capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34794#M25542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Q1. Where is unknown pcap stored?&lt;SPAN style="line-height: 1.5em;"&gt;[Device] &amp;gt; [Setup] &amp;gt; [Management] &amp;gt; [ Logging and Reporting Settings]&lt;/SPAN&gt;App Pkt Capture ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Application PCAPs are stored&amp;nbsp; at the following path&lt;STRONG&gt; /opt/panlogs/session/pan/application/ &lt;/STRONG&gt;.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;These&amp;nbsp; PCAPs will appear in the traffic log as a little green arrow .&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;You can use the&amp;nbsp; CLI command &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;view-pcap&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt; application-pcap&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt; &amp;lt;date&amp;gt;/"&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; to view the Application pcaps&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;[Device] &amp;gt; [Setup] &amp;gt; [Management] &amp;gt; [ Logging and Reporting Settings] is where you can alter the Storage Quota for various logs and PCAPs &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Q2. I want know Unknown Pcap Usage.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Can be viewed using CLI command :&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;gt; show system logdb-quota&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quotas:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; traffic: 32.00%, 38.060 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; threat: 16.00%, 19.030 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system: 4.00%, 4.758 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; config: 4.00%, 4.758 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alarm: 3.00%, 3.568 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; trsum: 7.00%, 8.326 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlytrsum: 3.00%, 3.568 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailytrsum: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklytrsum: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; thsum: 2.00%, 2.379 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlythsum: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailythsum: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklythsum: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; appstat: 6.00%, 7.136 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userid: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hipmatch: 3.00%, 3.568 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; application-pcaps: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; threat-pcaps: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp; debug-filter-pcaps: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hip-reports: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dlp-logs: 1.00%, 1.189 GB&lt;/P&gt;&lt;P&gt;Disk usage:&lt;/P&gt;&lt;P&gt;traffic: Logs: 59M, Index: 14M&lt;/P&gt;&lt;P&gt;threat: Logs: 42M, Index: 12M&lt;/P&gt;&lt;P&gt;system: Logs: 5.6M, Index: 904K&lt;/P&gt;&lt;P&gt;config: Logs: 17M, Index: 184K&lt;/P&gt;&lt;P&gt;alarm: Logs: 20K, Index: 20K&lt;/P&gt;&lt;P&gt;trsum: Logs: 86M, Index: 4.1M&lt;/P&gt;&lt;P&gt;hourlytrsum: Logs: 2.7M, Index: 1.5M&lt;/P&gt;&lt;P&gt;dailytrsum: Logs: 944K, Index: 1.4M&lt;/P&gt;&lt;P&gt;weeklytrsum: Logs: 468K, Index: 224K&lt;/P&gt;&lt;P&gt;thsum: Logs: 192K, Index: 192K&lt;/P&gt;&lt;P&gt;hourlythsum: Logs: 176K, Index: 176K&lt;/P&gt;&lt;P&gt;dailythsum: Logs: 168K, Index: 168K&lt;/P&gt;&lt;P&gt;weeklythsum: Logs: 32K, Index: 32K&lt;/P&gt;&lt;P&gt;appstatdb: Logs: 1.1M, Index: 852K&lt;/P&gt;&lt;P&gt;userid: Logs: 100K, Index: 52K&lt;/P&gt;&lt;P&gt;hipmatch: Logs: 20K, Index: 20K&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;application-pcaps: 1.4M &lt;/STRONG&gt;&lt;/SPAN&gt; &amp;lt;&amp;lt;====&lt;STRONG&gt;App PCAP usage&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;threat-pcaps: 4.0K&lt;/P&gt;&lt;P&gt;debug-filter-pcaps: 12K&lt;/P&gt;&lt;P&gt;dlp-logs: 4.0K&lt;/P&gt;&lt;P&gt;hip-reports: 1.1M&lt;/P&gt;&lt;P&gt;wildfire: 16K&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Q3. When is capture unknown packet in PA packet flow?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="line-height: 1.5em;"&gt;When PA firewall is unable to identify the application using APP-ID ,the application will be termed as unknown (unknown/&lt;/SPAN&gt;-tcp,unknown-udp,non-sysn-tcp).&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="line-height: 1.5em;"&gt;Following Tech &lt;/SPAN&gt;note will give you detailed Information about unknown apps and how to report them to Palto Alto.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A __default_attr="2007" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 07:28:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34794#M25542</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-08-05T07:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown Application Packet Capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34795#M25543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following doc explains about unknow apps&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2007"&gt;https://live.paloaltonetworks.com/docs/DOC-2007&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also following document explains how to request an new application&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1879"&gt;https://live.paloaltonetworks.com/docs/DOC-1879&lt;/A&gt;&lt;/P&gt;&lt;P&gt;you can also create an app override for an application that is internal to your network and you know the port numbers&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;https://live.paloaltonetworks.com/docs/DOC-1071&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Following doc explains what application override does&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1343"&gt;https://live.paloaltonetworks.com/docs/DOC-1343&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 05:37:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unknown-application-packet-capture/m-p/34795#M25543</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-06T05:37:53Z</dc:date>
    </item>
  </channel>
</rss>

