<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159381#M52107</link>
    <description>&lt;P&gt;I'm not sure if I understood your requirements correctly. Do you need almost the raw traffic log? Or the cumulated traffic/bytes per src:dst ip pair? Or more like subnet:dst ip pair?&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jun 2017 17:59:30 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-06-04T17:59:30Z</dc:date>
    <item>
      <title>Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159373#M52105</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a simple 'tenanted' environment.&amp;nbsp; A /24 subnet represents a tenant behind the trust of my PAN.&lt;/P&gt;&lt;P&gt;I want a simple report that shows 'traffic' over the last calendar month of that /24.&lt;/P&gt;&lt;P&gt;I think this is simple by applying a 'monitor tag' per subnet.&amp;nbsp; And then tagging my basic permit rules that match that source condition match of that /24 with that 'monitor tag'.&lt;/P&gt;&lt;P&gt;But this 'sort by' and 'group by' is annoying.&amp;nbsp; I don't want to sort or group by anything.&lt;/P&gt;&lt;P&gt;I literally want a 'database = traffic' based custom report where selected columns are (top down)&lt;/P&gt;&lt;P&gt;- Monitor Tag&lt;/P&gt;&lt;P&gt;- Source address&lt;/P&gt;&lt;P&gt;- Destination address&lt;/P&gt;&lt;P&gt;- Bytes&lt;/P&gt;&lt;P&gt;with no grouping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See what i'm trying to do ?&lt;/P&gt;&lt;P&gt;The sort by is giving me a finite display of rows.&amp;nbsp; I just want a total bytes of every vlan/subnet.&lt;/P&gt;&lt;P&gt;Any suggestions from the community ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9525i41170520D91C6BAD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2017 10:59:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159373#M52105</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-06-04T10:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159381#M52107</link>
      <description>&lt;P&gt;I'm not sure if I understood your requirements correctly. Do you need almost the raw traffic log? Or the cumulated traffic/bytes per src:dst ip pair? Or more like subnet:dst ip pair?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jun 2017 17:59:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159381#M52107</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-04T17:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159389#M52108</link>
      <description>&lt;P&gt;I'd love to be able to,&lt;/P&gt;&lt;P&gt;1. Tag all my policies that match a source condition of a tenant /24 with a tag.&amp;nbsp; I.e. (Some have some whitelisting of 'org wide prohibited apps' , above an org wide block list of say spotify, etc) .. so would have 2 or 3 rules above &amp;amp; beyond the sourceNAT allow at the bottom.&lt;/P&gt;&lt;P&gt;2. then based on that tag want to build a custom report of cumulative BYTES showing columns of, 1. That tag, 2. Source IP, 3. Destination IP, 4. Bytes for 'calendar month'.&lt;/P&gt;&lt;P&gt;3. no grouping or filtering.&amp;nbsp; Just cumulative BYTES on that tag.&amp;nbsp; If I have 100 tags then I have 100 rows.&lt;/P&gt;&lt;P&gt;100 rows, 4 columns.&lt;/P&gt;&lt;P&gt;If I tack on additional tenants.. then rows will grow, but 4 columns remain/are static.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 01:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159389#M52108</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-06-05T01:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159441#M52120</link>
      <description>&lt;P&gt;What if you set the group by to "Rule", and the number to as many as you need and add the columns "rule" and "bytes" to the report. This way (if you have only one rule / tenant) it will give you what you need right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I assume that you have more than one rule / tenant, so to get exactly what you need I think you have the following options:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use an external log analyzing software like splunk&lt;/LI&gt;&lt;LI&gt;Create 1 custom report / tenant, collect the outputs with a script periodically with the API and let the same script merge the outputs from the different custom reports to one file (for example csv)&lt;/LI&gt;&lt;LI&gt;Use the API to build a totally custom solution where you create a script to parse the logs anf get the information you need do things like cumulating the bytes for every entry / tenant&lt;/LI&gt;&lt;LI&gt;Reach out to your SE to create a Feature Request and wait ...&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 05 Jun 2017 10:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159441#M52120</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-05T10:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159442#M52121</link>
      <description>&lt;P&gt;I reckon Ileveraging the API is the best bet.&lt;/P&gt;&lt;P&gt;But tell me.. how does the 'Monitor Tag' work ?&lt;/P&gt;&lt;P&gt;That will be key in querying against when parsing and summating manually in the API... me thinks (for my use case/requirement for the report).&lt;/P&gt;&lt;P&gt;But the reference to the humble 'tag' in PANOS 8.0 doco references it only to 'SaaS Application Usage' ? &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/objects/objects-tags" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/objects/objects-tags&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 11:35:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159442#M52121</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-06-05T11:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Report; 'bytes' per 'vlan'/ '/24 subnet' with ? monitor tag ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159444#M52122</link>
      <description>&lt;P&gt;These tags are only for tagging objects/rule. This way you are able to search after a tag and your firewall/panorama will show all related things. Or to as you probably meant, create a tag / tenant and use this tag to identify the specific tenantrules. The tags cannot be used for log querys.&lt;/P&gt;&lt;P&gt;But if you go the way with the API you have to use the filter (addr.src in tenant/24) and then use the logs returned by the API to calculate the things you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a very simplified option how I think this can be solved (pseudo code):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$logs = get-fw-logs((addr.src in 10.0.0.0/24) and (action eq allow))&lt;/P&gt;&lt;P&gt;[int64]$bytes&lt;/P&gt;&lt;P&gt;Foreach ($entry in $logs) {&lt;/P&gt;&lt;P&gt;$bytes += $entry.bytes&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on how many logs you have there will also be some more problems because the API will return entrys up to a specified max. (Which I can't remember right now). So you probably have to issue more than one query to get all logs you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 11:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-report-bytes-per-vlan-24-subnet-with-monitor-tag/m-p/159444#M52122</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-05T11:58:27Z</dc:date>
    </item>
  </channel>
</rss>

