<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44341#M32541</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the scenario:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; 1 week ago, a session from 10.1.1.1 and 10.2.2.2 is established.&amp;nbsp; Normally, data transfer is very low.&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; Within that session, 100GB of data is suddenly transferred one day between 6pm and 7pm, pegging the site's Internet bandwidth.&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; The data transfer becomes very low again after the burst. The session doesn't terminate until 1 week later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Observations:&lt;/P&gt;&lt;P&gt;- If we look at ACC during that 1 hour burst, the traffic doesn't show up at all.&lt;/P&gt;&lt;P&gt;- If we look at the session browser, all we see is total transferred bytes since the session was established.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;- When we try to figure out what's using up the bandwidth in a particular time frame, how can we see bytes transferred and source/destination IPs for established sessions that remain active?&lt;/P&gt;&lt;P&gt;(The Network Monitor is horribly inflexible and doesn't produce enough detail to be useful in our actual scenario)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Dec 2014 06:26:17 GMT</pubDate>
    <dc:creator>RyanF</dc:creator>
    <dc:date>2014-12-04T06:26:17Z</dc:date>
    <item>
      <title>Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44341#M32541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the scenario:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; 1 week ago, a session from 10.1.1.1 and 10.2.2.2 is established.&amp;nbsp; Normally, data transfer is very low.&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; Within that session, 100GB of data is suddenly transferred one day between 6pm and 7pm, pegging the site's Internet bandwidth.&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; The data transfer becomes very low again after the burst. The session doesn't terminate until 1 week later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Observations:&lt;/P&gt;&lt;P&gt;- If we look at ACC during that 1 hour burst, the traffic doesn't show up at all.&lt;/P&gt;&lt;P&gt;- If we look at the session browser, all we see is total transferred bytes since the session was established.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;- When we try to figure out what's using up the bandwidth in a particular time frame, how can we see bytes transferred and source/destination IPs for established sessions that remain active?&lt;/P&gt;&lt;P&gt;(The Network Monitor is horribly inflexible and doesn't produce enough detail to be useful in our actual scenario)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2014 06:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44341#M32541</guid>
      <dc:creator>RyanF</dc:creator>
      <dc:date>2014-12-04T06:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44342#M32542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if we can get proper information for that particular hour .&lt;/P&gt;&lt;P&gt;But you can try one thing. You can create a report for this particular source and destination address. I hope this will give you some information .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="report.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17146_report.JPG" style="height: 396px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;From the available column you can select source address, destination address, hour ,application , bytes sent,bytes received.&lt;/P&gt;&lt;P&gt;In the query builder you can specify the specific source and destination address.&lt;/P&gt;&lt;P&gt;So you will have to generate multiple reports with different time frames like 24 hours , one week . Test with different columns too.&lt;/P&gt;&lt;P&gt;I am not sure if&amp;nbsp; we will be able to find out something specific for this time , but for future if you want to track something like this for the previous one hour or six hours, 12 hours ,we can do that .&lt;/P&gt;&lt;P&gt;Let me know if it was helpful ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2014 22:14:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44342#M32542</guid>
      <dc:creator>MSharma</dc:creator>
      <dc:date>2014-12-04T22:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44343#M32543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is, we don't know what IPs we need to investigate.&amp;nbsp; The ultimate question is, how can we accurately see bytes transferred (and source/destination IPs) in a given period of time?&amp;nbsp; The data transferred with established (non-terminated) sessions don't show up in any report, which could be a huge missing piece.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Dec 2014 20:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44343#M32543</guid>
      <dc:creator>RyanF</dc:creator>
      <dc:date>2014-12-08T20:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44344#M32544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My understanding is that ACC is based upon log data; and the log entry with the amount of data transferred is only created at session end - so ACC (and Traffic Logs) are no use mid-way through a flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exporting Netflow data from your firewall to a Netflow collector is most likely the answer to this problem.&amp;nbsp; I'd hope that PA's Netflow implementation will send out flow entries for in-progress sessions - but I've not used Netflow on PA to confirm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2014 16:59:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44344#M32544</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-12-12T16:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44345#M32545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In what I've seen so far, I think you are correct--only Netflow can provide what we need here.&amp;nbsp; A shame that's not built-in to Panorama.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Dec 2014 17:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44345#M32545</guid>
      <dc:creator>RyanF</dc:creator>
      <dc:date>2014-12-15T17:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Active session traffic seems invisible to ACC.  Any way to see bytes transferred of active sessions in a period of time? (Not using network monitor)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44346#M32546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if its a long session it won't log until the session closes so make sure log at session start &amp;amp; log at session end are both selected for the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this as well &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the traffic logs and enable views for 'bytes sent' 'bytes received' , packets sent &amp;amp; packets received&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set the filter to 'bytes geg 10000000' will show you bytes uploads greater than 10mb&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unit is in bytes&lt;/P&gt;&lt;P&gt;geq = greater than or equal&lt;/P&gt;&lt;P&gt;leq = less than or equal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can also use 'bytes_sent geg 1000' or 'bytes_received geq'1000'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will show all traffic that had a bytes sent greater than 100kb you can also increase decrease and continue to filter down in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is how i detect large uploads or large downloads&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can do the same with packet but bytes is easier imo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Dec 2014 04:33:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-session-traffic-seems-invisible-to-acc-any-way-to-see/m-p/44346#M32546</guid>
      <dc:creator>jkim2</dc:creator>
      <dc:date>2014-12-19T04:33:28Z</dc:date>
    </item>
  </channel>
</rss>

