Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command

scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv

on my PA220. 

 

root@Expedition:/PALogs# ls -l
total 64296
-rw-rw-r-- 1 expe

...

Untitled.png
mbowling by L1 Bithead
  • 37958 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW):

https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c

 

Be sure to go Settings > M. Learning > and change the Expedition ML Addr

...

trice by L1 Bithead
  • 58144 Views
  • 45 replies
  • 22 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini

 

sudo vi /etc/php/7.0/apache2/php.ini go to line where this ...

alestevez by L7 Applicator
  • 25532 Views
  • 5 replies
  • 11 Likes

Resolved! Expedition ML rules with any/any

After a week of logs from a NGFW I tryed to ML rules from it and got a couple of "suspicious" rules, for example these two below:

 

 In these, as you can see, the source, destination and service are any. What is the threshold that makes Expedition c

...

Capture.PNG

Expedition vm missing

I have vm fusion on a mac and the vm disappeared, but I found it on the drive but all projects were gone. Is there an issue with vmware fusion on mac, are the project files recoverable? thanks

App reconciliation not working App-id via log

Hi.

 

Trying to applifie some rule with expedition, and prior to 1.0.107 this worked fine.

What im doing is adding Device, and Creating a project.

Importing the configuration.

Choose a rule to applifie and Retrive Apps on selected rule. I can see the

...

dgradin by L0 Member
  • 2375 Views
  • 0 replies
  • 0 Likes

Statistics from a Panorama controlled FW

Hi'

 

Anyone know how to get Expedition to show project statistics for only one FW in a Panorama setup with several firewalls.

 

I got a new migrated firewall imported into Panorama and now its time to clean up and do some (a lot) enrichment/adoption

...

ASA to PAN - Security Rule Based on pre-NAT Issue

Not sure if anyone else ran into this.

 

ASA's security policies are built based on post-NAT rules (post 8.3 OS)

 

With the tool, it builds the same rules with the post-NAT rules, private IP ... which will not work with PAN as the rule is built based

...

ROHO by L2 Linker
  • 4298 Views
  • 3 replies
  • 0 Likes

Using Fusion to generate an Expedition OVA

If you're looking to deploy Expedition into an ESXi environment you can use Fusion to convert the Expedition vmdk to an OVA format using the steps below. 

 

I am running Fusion ver 10.1.3

 

________ 

 

YOU = Your username on your Mac

 

To deploy the

...

sjanita by L5 Sessionator
  • 2392 Views
  • 0 replies
  • 0 Likes

Resolved! ASA Migration - TCP/UDP source port rules not migrated

Noticed that many rules with source ports defined are not migrated over. 

 

Instead, it creates a service only for the destination port/range and allows all ports through.

 

Below are a few rules. Is it a known behavior?

 

The first two allowed all u

...

ROHO by L2 Linker
  • 4043 Views
  • 2 replies
  • 0 Likes

ASA Migration - Zones

We are in process of migrating ASA config to Palo Alto (multiple context asa to multiple vsys)

 

Loading the config into Expedition works fine and we are able to remap interfaces and rename zones that are too long in characters. However, when loading

...

skfigved by L0 Member
  • 3223 Views
  • 1 replies
  • 0 Likes

Resolved! Expedition and CPUs

Greetings,

 

I have assigned 4 CPUs to my Expedition VM, verified by checking /proc/cpuinfo.

When I log into Expedition, it reports 1 of 1 CPUs and CPU usafge is 101 of 100%.

Can someone please explain this difference between what Expedition is repor

...

mrzepa2 by L2 Linker
  • 6955 Views
  • 2 replies
  • 0 Likes
  • 1125 Posts
  • 79 Subscriptions
Top Solution Authors
Top Liked Authors
Labels