Expedition Discussions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Expedition Discussions

Discussions

Resolved! ML gets stuck at "Pending"

I started by running the command scp export log traffic start-time equal 2018/07/30@00:00:00 end-time equal 2018/07/30@23:45:00 to expedition@172.30.200.117:/PALogs/mltest.csv on my PA220. root@Expedition:/PALogs# ls -ltotal 64296-rw-rw-r-- 1 expedition expedition 65830760 Aug 1 17:35 mltest.csvdrwxr-xr-x 2 www-data www-data 4096 Aug 1 ...

Untitled.png
mbowling by L1 Bithead
  • 46173 Views
  • 26 replies
  • 3 Likes

If You Need an OVA...

I created an OVA for my team and put it up here (Note, this isn't the official release now offered by PANW): https://drive.google.com/open?id=1Z9GrCF8I_BZzpbEmEh6G75npo05_4G0c Be sure to go Settings > M. Learning > and change the Expedition ML Address address to your VM's IP. Then return to the Dashboad and Start the Agent. [UPDATE 6.4...

trice by L1 Bithead
  • 73013 Views
  • 46 replies
  • 23 Likes

Resolved! How to Upload configuration files bigger than 2MB

Expedition uses APACHE as a web server and PHP as module for the scripts. By default PHP allow users to upload files with a maximum size of 2M, this can be updated by changing the PHP.ini sudo vi /etc/php/7.0/apache2/php.ini go to line where this variable is defined upload_max_filesize = 2M and replace by upload_max_filesize = 250M There...

alestevez by L7 Applicator
  • 30127 Views
  • 5 replies
  • 11 Likes

Resolved! RE error_SecRulesEnrich No traffic found

I have a problem with Rule Enrichment. The error_SecRulesEnrich gives these messages after analysing the data from a rule which has a lot of data (at least by APP-ID): I am connected to a firewall, and i can analyse in Expedition the applications (By APP-ID) and getting results. So i am confused why it sais, no traffic found. MySQL is...

Schermafbeelding 2018-10-29 om 15.36.56.png
antono by L1 Bithead
  • 6824 Views
  • 5 replies
  • 0 Likes

BP - How does Remediate work?

How does the Best Practice remediate function work? I cannot find any documentation. Do I have to select the specific option in the template first or will Expedition/BP remediate all the rd x-ed optioons without asking? While using Remediate and chose "SAME Template" how can I update the Panorama/Device configuration? Where is the template sto...

Resolved! Adding Security Profile Group to Policies

Converting from ASA to PAN. Is there a way to apply a Security Profile Group to a large # of security policies. One can only create a snippet for the individual profiles but not for a group. Tried to edit the policy itself and manually add a group name. It took it, but when we open the policy back up, it is not there. One mentioned to crat...

ROHO by L2 Linker
  • 11249 Views
  • 8 replies
  • 0 Likes

Expedition Storage

I think that Expedition is reporting storage incorrectly: both /home/userSpace and /temp are stated as using 58.9% of unit space. Also, how do I delete App-ID logs?

2018-10-24_9-00-39.png
dega by L2 Linker
  • 3583 Views
  • 1 replies
  • 0 Likes

Resolved! BPA Tool Not Running?

Am trying to run BPA from Expedition against a PAN baseline config. Imported the config and clicked on Start Analysis from the Dashboard. It says it is complete, but is 0% for everything. There is no content/results in the Analysis, Security Policies, and Threat Practice section.

ROHO by L2 Linker
  • 6594 Views
  • 3 replies
  • 0 Likes

Inconsistent BPA Results

I am getting unexpected results with Best Practice Analysis. For instance, Going to Best Practice > Security Policies shows red X for all tags and many descriptions, but the majority of my policies have both. Also, the adoption diagram shows 0% for High Availability, but I have HA configured to nearly all best practice specifications. Dynam...

magates by L2 Linker
  • 10461 Views
  • 8 replies
  • 0 Likes

Migration from Cisco ASA to Palo Alto

Hello Everyone, Using Expedition tool to migrate from Cisco ASA to Palo Alto-- it is not migrating completely-- receiving output as .xml only few configurations are shown after migration. Please give any suggestions to migrate the complete configuration. Thanks in advance.

Resolved! Expedition as OVA or OVF?

Dear All, does somebody know when Expedition will be available as OVA or OFV File? Our VMWare Admin denies the implementation or the current downloadable Expedition Tool. Best Regards René from Germany

Resolved! Firewall / Panorama traffic-log via Syslog to Expedition

Hello, i'm forwarding at the moment traffic logs from Palo Firewalls and Panorama to the Expedition server. I verified with tcpdump that the Expedition-Server recieves the syslogs. Expedition is up to date. I modified the configuration files in "/var/www/html/OS/rsyslog" like described in the "Expedition Log Analysis Guide v1.0". I also chan...

bebe5001 by L0 Member
  • 7060 Views
  • 3 replies
  • 0 Likes

File "filename.xml" is malformed

Hello, wanted to see if anyone has ran into this issue. After merging and generating the configuration. The load result on the firewall fails with file is malformed. Looking at the xml the configuration doesn't look correct, the top line reads - "coding="ISO-8859-1"?>" and the configuration spacing is not correct, and missing most of the...

  • 1185 Posts
  • 89 Subscriptions
Labels