<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Total Application Time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179030#M55629</link>
    <description>&lt;P&gt;This is great! Though I do run into accuracy issues, as has been mentioned, after running some tests. A lot of my traffic is encrypted too, so it shows up as SSL traffic and not YouTube. Though I did some see some application traffic for YouTube over 443, which I find interesting. Why does some of it show up as SSL and some as YouTube, both over 443? I would obviously need SSL decryption to dig deeper into the SSL traffic.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Sep 2017 21:11:01 GMT</pubDate>
    <dc:creator>mario11584</dc:creator>
    <dc:date>2017-09-27T21:11:01Z</dc:date>
    <item>
      <title>Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/178989#M55620</link>
      <description>&lt;P&gt;I'm trying to figure out the total application time of some specific applications. For example, for the last 7 days I'd like to know for a particular subnet how much time was spent on YouTube. Is this possible? So I'm looking for something to tell me that there has been a total of 8 hours, for example, of YouTube sessions for the last 7 days. I can find session count, I can find bytes, but I can't find anything that takes all the session duration data the PA has and give it back to me in this way.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 18:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/178989#M55620</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2017-09-27T18:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179000#M55621</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7997"&gt;@mario11584&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That is currently not directly supported by Palo Alto. I would recommend adding your vote to the requisite future request via your SE, I'm sure there is already one out there for this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 18:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179000#M55621</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-27T18:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179003#M55622</link>
      <description>&lt;P&gt;Elapsed time might help you out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Elapsed Time.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11571i85D5C7884FBA2F7E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Elapsed Time.PNG" alt="Elapsed Time.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 18:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179003#M55622</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-27T18:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179004#M55623</link>
      <description>&lt;P&gt;Here's a couple of ways to try and figure this out:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.) Custom Reporting.&amp;nbsp; You can create a custom report from the traffic log where the (app eq youtube) and the (addr.src in 10.1.2.0/24) and include "Elapsed Time" in the selected columns:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yt1.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11568iC47917B12814BA6E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="yt1.png" alt="yt1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That would give you a report that looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yt2.png" style="width: 354px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11569i673A1EC185A20FE4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="yt2.png" alt="yt2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind that this value includes more than just the actual "stream" elapsed time.&amp;nbsp; This is elapsed time for all TCP sessions where the application was Youtube.&amp;nbsp; Some of those sessions could be static pages, ads, pre-loading the next video that wasn't watched, etc.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.) User Activity Reporting:&amp;nbsp; This doesn't necessarily work by subnet, though.&amp;nbsp; If you could put all of the users of the subnet in question into a single LDAP group, then you could do a group activity report - and there's an estimated 'browse time' column for the URL's visited by that group.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3.) Rough Math:&amp;nbsp; Figure out what the average MB/minute is for Youtube, then run a traffic report determining total Youtube traffic for that Subnet.&amp;nbsp; Divide that by the MB/minute and you get total minutes of Youtube.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reporting pro-tip:&amp;nbsp; No matter which way you go, I'd highly recommend using yourself as a guinea pig.&amp;nbsp; Watch youtube videos for 15 minutes and then run each of these reports against yourself to determine what kind of "fudge-factor" you'll need to include with the results.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 18:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179004#M55623</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-09-27T18:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179006#M55624</link>
      <description>&lt;P&gt;This is one of those things that everyone wants but no one can truly deliver without a client monitor (and even then it's not often accurate).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are some examples of how reporting on actual browse time can be a challenge:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User has a playlist loaded on a tab but isn't actually watching videos actively (maybe a music playlist)&lt;/LI&gt;&lt;LI&gt;User is browsing a web forum with embedded YouTube videos that autoplay.&lt;/LI&gt;&lt;LI&gt;User is watching YouTube on their phone while working (assuming phone is on the same subnet as their computer)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are only concerned about bandwidth, you can get good reports from the firewall for that. But translating YouTube session duration with actual time spent viewing videos isn't something that translates well with just traffic log analysis.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 18:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179006#M55624</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2017-09-27T18:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179030#M55629</link>
      <description>&lt;P&gt;This is great! Though I do run into accuracy issues, as has been mentioned, after running some tests. A lot of my traffic is encrypted too, so it shows up as SSL traffic and not YouTube. Though I did some see some application traffic for YouTube over 443, which I find interesting. Why does some of it show up as SSL and some as YouTube, both over 443? I would obviously need SSL decryption to dig deeper into the SSL traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 21:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179030#M55629</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2017-09-27T21:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179031#M55630</link>
      <description>&lt;P&gt;Chance are some of the traffic will also be tagged as "quic" - also on port 443.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 21:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179031#M55630</guid>
      <dc:creator>LucaMarchiori</dc:creator>
      <dc:date>2017-09-27T21:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Total Application Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179045#M55632</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7997"&gt;@mario11584&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;This is great! Though I do run into accuracy issues, as has been mentioned, after running some tests. A lot of my traffic is encrypted too, so it shows up as SSL traffic and not YouTube. Though I did some see some application traffic for YouTube over 443, which I find interesting. Why does some of it show up as SSL and some as YouTube, both over 443? I would obviously need SSL decryption to dig deeper into the SSL traffic.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabling SSL decryption&amp;nbsp;would make the report more accurate, but one does not "just" enable SSL decryption without testing first.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your other option is to get a better handle on how&amp;nbsp;the firewall sees Youtube traffic as a whole (app-id=youtube, app-id=ssl+some other indicator, etc.)&amp;nbsp;&amp;nbsp;Does the actual video stream get tagged as "youtube" or "ssl"?&amp;nbsp; If it is identified as youtube, that makes it easy for your reporting goals.&amp;nbsp; If the stream is identified as ssl (or a mix of the two), then you'll need to dig deeper into your logs to figure out what's going on.&amp;nbsp; (I recommend using the unified log viewer and adding both the URL and Session ID colums to the list).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be that the Youtube app-id needs some updating/additional coverage - in which case open a support ticket.&amp;nbsp; It could be that only decryption will resolve this issue.&amp;nbsp; Or finally, you could find some additional information in the unified logs that allows you to generate a&amp;nbsp;report combining all youtube and specific ssl traffic together.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 22:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-application-time/m-p/179045#M55632</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-09-27T22:52:06Z</dc:date>
    </item>
  </channel>
</rss>

