EXPEDITION : ML is not able to Parse connection logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

EXPEDITION : ML is not able to Parse connection logs

L0 Member

Hello

 

I am not able to use the ML functionnality on imported log trafic.

melvynguibout_0-1710339413963.png

Spark tasks are skipped..

 

I have nothing in those directories : 

melvynguibout_1-1710339547972.png

 

Log files are in PALogs/

PALogs directory is owned by www-data.

 

Here is my ML menu when i try to analyse data : 

 

melvynguibout_2-1710339762872.png

(nothing unusual)

But there is nothing in the output.

 

 

How can i pinpoint the problem more precisely since i have no error logs ?

 

Thank you,

 

Melvyn

3 REPLIES 3

L4 Transporter

Hi @melvyn-guibout 

 

Let me suggest some troubleshooting:

 

1) Check that the logs are analysed so you have a folder /data/ with the parquet files. That folder shall be owned by www-data:www-data.

2) Check that the serial displayed in the "Connectors" match with the serial on the analysed logs.

3) Check the generated logs in /tmp/ folder.

 

ML Logs

 

File

Content

/tmp/command.spark

External cli command to execute spark 

/tmp/error_SecRulesLearn

Standard output execution log for ML process

/tmp/error_SecRulesLearn2

Error output execution log for ML process

 

RE Logs

 

File

Content

/tmp/command.spark

External cli command to execute spark 

/tmp/error_SecRulesEnrich

Standard output execution log for RE process

/tmp/error_SecRulesEnrich2

Error output execution log for RE process

 

Let me know if you need anything else,

 

Best,

  

You may find hints in /tmp/error_SecRulesLearn.

Our Panorama is M300, which is not available in the drop down menu, so I gave it a try with M600, but no output. We had to change the model type to VM, then it worked.

Hi @C.Pfitzer@melvyn-guibout 

To be able to create properly the log connector, if the configuration is from a Panorama, on the device model select vm-panorama.

Thanks!

David

  • 1246 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!