<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log forwarding to CDL is generating high traffic volume in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417580#M93573</link>
    <description>&lt;P&gt;If you're a Cortex Pro customer as well, the usage by Data Lake will be high. Just QoS the app on the box, give it a set bandwidth if it's causing troubles. (&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/configure-qos.html" target="_self"&gt;docs&lt;/A&gt;)&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jul 2021 17:28:39 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2021-07-07T17:28:39Z</dc:date>
    <item>
      <title>log forwarding to CDL is generating high traffic volume</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417360#M93534</link>
      <description>&lt;P&gt;Dear community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are sending logs to cortex data lake and we noticed high traffic volume for the sessions concerning log forwarding, with peaks up to 200GB of data sent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if this volume of traffic can be normal?&lt;/P&gt;&lt;P&gt;Also, is there any documentation on how logs are being sent to CDL or how would you troubleshoot this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 22:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417360#M93534</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-07-06T22:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to CDL is generating high traffic volume</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417562#M93567</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check your log sources for what they are sending. If its the Firewalls, make sure you are only logging at session end. Also you can filter what is sent to the data lake, if you wish to limit the data, but its a data lake so I say the more the merrier.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 16:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417562#M93567</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-07-07T16:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to CDL is generating high traffic volume</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417580#M93573</link>
      <description>&lt;P&gt;If you're a Cortex Pro customer as well, the usage by Data Lake will be high. Just QoS the app on the box, give it a set bandwidth if it's causing troubles. (&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/configure-qos.html" target="_self"&gt;docs&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 17:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417580#M93573</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-07-07T17:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to CDL is generating high traffic volume</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417601#M93577</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/186790"&gt;@Bearden&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for this question, but could you explain thia again? I don't understand what you are trying to tell us.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 19:45:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417601#M93577</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-07T19:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to CDL is generating high traffic volume</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417602#M93578</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Over what time do you see these 200 GB peaks or also where? Is this from the ACC tab on the firewall? In that case you might see the end of a session which was open for days or even weeks and these 200 GB were the result of this very long session.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 19:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417602#M93578</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-07T19:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: log forwarding to CDL is generating high traffic volume</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417987#M93620</link>
      <description>&lt;P&gt;Yes, those are sessions that stay alive for over a week.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some sessions I see also that bytes received from CDL are almost the same as bytes sent from the firewall. Is this because of log acknowledgment? If yes, how possible is so big the ack?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 22:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-cdl-is-generating-high-traffic-volume/m-p/417987#M93620</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-07-08T22:58:49Z</dc:date>
    </item>
  </channel>
</rss>

