<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to identify long live session(s) ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92171#M43697</link>
    <description>&lt;P&gt;I think session table shows up to 1024 sessions at once.&lt;/P&gt;&lt;P&gt;If you don't have too many sessions then you could export from cli.&lt;/P&gt;&lt;P&gt;show session all start-at 1&lt;/P&gt;&lt;P&gt;show session all start-at 1025&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way ACC data comes directly from dataplane and it does not matter if sec policy has "log at session start" and "log at session end" checked - ACC still shows everything. ACC is not real time - it has 15 min delay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 25 Jun 2016 15:25:28 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-06-25T15:25:28Z</dc:date>
    <item>
      <title>How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92145#M43694</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to identify those long live sessions on my firewall, &amp;nbsp;I mean those session(s) that never ended for weeks at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I found out so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. &amp;nbsp;I can't export the whole session log to perform offline analysis,&lt;/P&gt;&lt;P&gt;2, &amp;nbsp;I did not find anything related to session start time as filter under show session all filter.&lt;/P&gt;&lt;P&gt;3. &amp;nbsp;ACC will only record when a session is closed, I don't believe ACC will show that session data (session #, packets used, bytes used) until the session is ended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advanced,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2016 11:56:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92145#M43694</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-25T11:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92171#M43697</link>
      <description>&lt;P&gt;I think session table shows up to 1024 sessions at once.&lt;/P&gt;&lt;P&gt;If you don't have too many sessions then you could export from cli.&lt;/P&gt;&lt;P&gt;show session all start-at 1&lt;/P&gt;&lt;P&gt;show session all start-at 1025&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way ACC data comes directly from dataplane and it does not matter if sec policy has "log at session start" and "log at session end" checked - ACC still shows everything. ACC is not real time - it has 15 min delay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2016 15:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92171#M43697</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-25T15:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92191#M43700</link>
      <description>&lt;P&gt;Raido,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought about that, but the firewall have about 1 million active sessions &amp;nbsp;+/- &amp;nbsp;250k at any given time. &amp;nbsp; &amp;nbsp;I was trying to look up how does ACC work, do you have a link to a techdoc? &amp;nbsp; For sure, &amp;nbsp;I am seeing long live session does not show up on ACC until the session is closed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-E&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2016 17:53:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92191#M43700</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-25T17:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92336#M43710</link>
      <description>&lt;P&gt;How about using custom report?&lt;/P&gt;&lt;P&gt;If you select 'traffic log (detailed log, not summary database), you can use one column named 'elapsed time (sec)'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 05:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92336#M43710</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2016-06-27T05:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92430#M43719</link>
      <description>&lt;P&gt;In this case all security policies should have "log at session start" that is not default.&lt;/P&gt;&lt;P&gt;It is nice option but writes a lot more log and log retention period is shorter.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 10:33:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92430#M43719</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-27T10:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92469#M43723</link>
      <description>&lt;P&gt;I will need to try the custom report. &amp;nbsp; Thanks for the tips.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 14:00:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/92469#M43723</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-27T14:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify long live session(s) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/541747#M111021</link>
      <description>&lt;P&gt;How about using the XML API calls on the firewall and filtering by min-age?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;604800 seconds is a week.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;/api/?type=op&amp;amp;cmd=&amp;lt;show&amp;gt;&amp;lt;session&amp;gt;&amp;lt;all&amp;gt;&amp;lt;filter&amp;gt;&amp;lt;min-age&amp;gt;604800&amp;lt;/min-age&amp;gt;&amp;lt;/filter&amp;gt;&amp;lt;/all&amp;gt;&amp;lt;/session&amp;gt;&amp;lt;/show&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 19:42:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-identify-long-live-session-s/m-p/541747#M111021</guid>
      <dc:creator>William-Wu</dc:creator>
      <dc:date>2023-05-10T19:42:18Z</dc:date>
    </item>
  </channel>
</rss>

