<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: big disparity between Detailed and Summary logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38290#M28042</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also you may read&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3481"&gt;Logging and Reporting Settings Definitions&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Sep 2014 14:30:25 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2014-09-23T14:30:25Z</dc:date>
    <item>
      <title>big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38288#M28040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran 2 Panorama reports, using the detailed and summary databases, on application usage over the last 24 hours (simple reports, just top Applications ranked by bytes, no filters) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the results were completely different e.g the figures for web-browsing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Summary: 720G&lt;/P&gt;&lt;P&gt;Detailed: 3.3T&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The detailed figure looks correct, why is the summary figure so out of line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously we have quite a lot of traffic and logs and running reports using the detailed database takes forever, I'd prefer to use the summary database but the figures are completely wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 14:09:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38288#M28040</guid>
      <dc:creator>LCMember2860</dc:creator>
      <dc:date>2014-09-23T14:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38289#M28041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi NOC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Summary and Detailed logs are totally different parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;The entries under the detailed traffic logs are purged at a faster rate than the summary traffic logs. The hourly, daily, and weekly summaries are roll ups of 15 minute summaries on an hourly basis and a roll up of the hourly summaries on a daily basis as well as a roll up of the daily summaries on a weekly basis. So as we continue to roll up data the results can become summarized even further. This can lead to greater discrepancies between summarized databases and non-summarized databases.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;You can also refer following threads for more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;A href="https://live.paloaltonetworks.com/message/29609"&gt;Traffic summary databese&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4347"&gt;Custom reports for Summary vs Detailed logs database&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 14:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38289#M28041</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T14:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38290#M28042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also you may read&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3481"&gt;Logging and Reporting Settings Definitions&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 14:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38290#M28042</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-23T14:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38291#M28043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming the detailed logs haven't been purged I would expect the figure for total bytes to be approximately the same in both databases (for the same query) - we have 8T of log storage with 60% allocated to the detailed logs so this shouldn't be an issue on a query only looking at the last 24 hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e.&amp;nbsp; if there is a steady 1G of web-browsing in a 15 minute period, this should get rolled up to be 4G for the 1 hour summary, 96G for the daily summary etc - or am I misunderstanding how the summary works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if some of the detailed logs had been purged I would then expect the figure for total bytes to be higher from the Summary database, not lower as we are seeing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 14:52:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38291#M28043</guid>
      <dc:creator>LCMember2860</dc:creator>
      <dc:date>2014-09-23T14:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38292#M28044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi NOC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide us disk utilization differences on your firewall for sumVsDetailed. That will be more clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2014 16:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38292#M28044</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-23T16:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38293#M28045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-09-24 at 12.45.34.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15723_Screen Shot 2014-09-24 at 12.45.34.png" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 11:48:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38293#M28045</guid>
      <dc:creator>LCMember2860</dc:creator>
      <dc:date>2014-09-24T11:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38294#M28046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi NOC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks alot for response, this explains allocation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to see data for comparison "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Even if some of the detailed logs had been purged I would then expect the figure for total bytes to be higher from the Summary database, not lower as we are seeing.&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 13:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38294#M28046</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-24T13:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: big disparity between Detailed and Summary logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38295#M28047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;which data would you like to see?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 16:12:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/big-disparity-between-detailed-and-summary-logs/m-p/38295#M28047</guid>
      <dc:creator>LCMember2860</dc:creator>
      <dc:date>2014-09-24T16:12:02Z</dc:date>
    </item>
  </channel>
</rss>

