<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incorrect PANORAMA health MonitorStatus in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/327708#M83382</link>
    <description>&lt;P&gt;I can update, this has been accepted by Palo as a feature update, so don't hold your breath, but we should see a change at some point.&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2020 08:13:49 GMT</pubDate>
    <dc:creator>djr</dc:creator>
    <dc:date>2020-05-13T08:13:49Z</dc:date>
    <item>
      <title>Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/248840#M70774</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you help me understanding of my device status correctly :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was looking at my device status in PANORAMA's beautiful featrure called "Deviating devices" list. I couldn't quite understand why it is reporting some of my PA devices as deviating from Baseline though it's not even close to the threshold values. for example it's reporting a device as deviating when it's memory is at 27%. Sometimes it's red even for the connections count 2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please help me understanding, if you come across this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Nagarjuna&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 02:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/248840#M70774</guid>
      <dc:creator>nagarjuna.b</dc:creator>
      <dc:date>2019-02-05T02:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/303662#M79029</link>
      <description>&lt;P&gt;So I have seen the same issue. I see that my primary HA firewall pair is listed, and the active firewall is deviating, but all of the metrics are low... 7k sessions, 22% cpu, 208 logs/sec. It's very strange.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 16:38:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/303662#M79029</guid>
      <dc:creator>Fr4nk4</dc:creator>
      <dc:date>2019-12-13T16:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/303744#M79045</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my understanding if firewall sees increases in traffic as compare to previous baseline even though threshold is not reached it show it &amp;nbsp;as red.&lt;/P&gt;&lt;P&gt;Lets see if someone chimes in about this behaviour.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2019 05:32:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/303744#M79045</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-14T05:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/308854#M80102</link>
      <description>&lt;P&gt;Hi , it's a bit of a slow reply I realise, but I have just been looking at how many warnings we are logging and it seems to me that the baselining calculation doesn't allow for variations caused by night time and weekend lulls.&amp;nbsp; The little graph it displays shows my supposedly deviating stats are following a fairly normal pattern, but the baseline is way too low for daytime activity levels.&amp;nbsp; I can only assume that's because it's an average over all time and the variation between my day and night is huge, as I would guess it is for most people.&amp;nbsp; It uses some standard deviation to calculate a tolerance, but that's far too conservative.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take an example of my logging rate, to the human eye you can see it's sticking to the normal pattern but because the rate drops to the low 100's overnight, the 2,000 rate in the daytime is way outside the baseline and tolerance.&amp;nbsp; Weekends just add to that imbalance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo, can you change the algorithm to take into account time of day variations?&amp;nbsp; I'm no mathmetician so don't know how, but at teh moment I am just having to ignore/filter out the deviating device logs as they trigger all the time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="lograte.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23773i75DBD6E3B6BAF2F6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="lograte.png" alt="lograte.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 11:30:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/308854#M80102</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2020-01-31T11:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/327708#M83382</link>
      <description>&lt;P&gt;I can update, this has been accepted by Palo as a feature update, so don't hold your breath, but we should see a change at some point.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 08:13:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/327708#M83382</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2020-05-13T08:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/532089#M109709</link>
      <description>&lt;P&gt;2,5 years later and still the issue present.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 12:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/532089#M109709</guid>
      <dc:creator>Kristaps.Bekers</dc:creator>
      <dc:date>2023-02-23T12:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/559735#M113500</link>
      <description>&lt;P&gt;Wheels of change move slow.&amp;nbsp; Is it possible to send all system logs to a syslog server EXCEPT these deviating device logs?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 17:11:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/559735#M113500</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2023-09-27T17:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect PANORAMA health MonitorStatus</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/559781#M113506</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182396"&gt;@Jason_Lieberman&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can exclude deviating device logs by placing:&amp;nbsp;!( eventid eq 'deviating-device' ) in the Filter field under: Panorama &amp;gt; Log Settings &amp;gt; System &amp;gt; [Profile Name].&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 22:10:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incorrect-panorama-health-monitorstatus/m-p/559781#M113506</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-27T22:10:47Z</dc:date>
    </item>
  </channel>
</rss>

