06-20-2019 10:57 AM
Trying to use Expedition to migrate port based rules to App-ID. I have imported the Panorama running config and added the Log Collector Plugin. I clone the rules and then select App-ID Adoption to retrieve Apps on my selected rules and Expedition generates the report but I never see any Applications populated. I aslo should add that we are using Cortex Data Lake for Logging in Panorama.
06-21-2019 02:06 PM
I will give that a try and respond with an update.
06-21-2019 03:04 PM
I should add that I am VPN'd into the customer network. Will the App-ID adoption work across VPN?
06-24-2019 01:24 AM
are you running Expedition on your laptop/local machine and accessing the cloud based Panorama via the VPN?
this connection should not cause an issue. The important connection is with Panorama connecting to the Cortex data lake to query the traffic log.
06-24-2019 05:46 AM
Yes, I have Expedition running on my laptop and am VPN'd into network. Panorama is installed on premise at customer network and connected to Cortex Data Lake. Panorama queries Corext Data LAke with no issues. However, when I run App-Id adoption to retrieve apps fast for Fast the quesry runs but nothing ever happens. I have selectred specific rules that I know are getting hits.
06-25-2019 07:19 AM
go ahead and send an email to fwmigrate 2 paloaltonetworks.com and we can schedule a time to run the debug on the query. Please reference this discussion when sending the email.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!