Expedition ML process Sumarization Rule with Network

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Expedition ML process Sumarization Rule with Network

L1 Bithead

Hello Team,

 

For my first post on the community !

For a customer case we want to use Expedition Palo in the aim to bulid security rules from permissive security rules.

Indeed, with an additional file we have the best practices (from IT service directly) about security rules to implement its. In the past time we built our own application (based on Python) to give the results.

This approach is similar to APG Tufin , and we want to join about this mecanism by the end.

 

In the POC architecture we got an issue on the Expedition process Machine Learning . For that we have followed the next instructions :

  • Import Logs from Logs firewall (ok)
  • Import backup of configuration file (ok)
  • Define the metrics on specific security rules in the goal to sumamarize them* (ok)

 

For the last point, we observed a different mecanism from our requirement.

In fact, we want to summarize some security rules by network. ML process got it but some cases must be excepted. In general the summarization is  wrong so.

Our question is : Does it possible to export the generated output files (files created) from CLI about the ML processing ?

Our goal is to control this step and bring some changes about that.

 

I join you ML process on Expedition and focus on the result. In target, we want to export this content including the red boxes. 

 

Thank you a lot !

 

2 REPLIES 2

L6 Presenter

@Stephane_Samba you can export the ML result in to an excel file

L1 Bithead

Thank you for your return but I know this feature. I'm searching to export the ML results from CLI (including much more files). From excel files output, that's only the results of security rules summarization .. Not need this content. I only try to know if there are some generated files during ML process (pre-process and post-process). In the aim to control ML process and it is possible to bring some settings incluing on this process. 

  • 1166 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!