M.Learning Analysis results empty

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

M.Learning Analysis results empty

L0 Member

Currently I have a Panorama managed firewall, I have added Panorama to Expedition (Running v1.2.86), and I am sending syslogs from the firewall to Expedition. Logs are showing up and are being processed:

 

chrisweakland_0-1713991396913.png

chrisweakland_1-1713991719571.png

 

 

I have a project created, Panorama configuration imported, I can see the ruleset for the firewall in question. I have the log connector set to Panorama and the device group for the firewall selected.

 

chrisweakland_2-1713991845736.png

 

In the policy, I have enabled ML on the rules I am interested in. However, when I run the analysis, I get an empty result:

chrisweakland_3-1713991913002.png

chrisweakland_0-1713993251600.png

 

 

Can anyone chime in on how to resolve this issue?

 

Thanks,

Chris

 

1 accepted solution

Accepted Solutions

L4 Transporter

Hi @chris.weakland I guess your issue is related to what @sanandh mentions regarding the FW serials matching. So besides his comments, please do below:

1) Edit your Panorama and set it up as "vm-panorama".

2) Open your project again, go to plugins and create a new log connector, in this case you should be able to select the device, the source file and the DG but also selecting the FWs. See attached screenshot for reference.

 

dpuigdomenec_0-1714035781709.png

Hope this helps,

David

 

 

View solution in original post

3 REPLIES 3

L2 Linker

There are couple of things to double check:
- Verify the logs have the serial number matching the serial used to initiate the ML analysis. In case of HA pairs, the logs could be using a different serial.

- Verify there are logs for the rule you are analyzing . If there are no matching logs, the analysis result will be empty

L4 Transporter

Hi @chris.weakland I guess your issue is related to what @sanandh mentions regarding the FW serials matching. So besides his comments, please do below:

1) Edit your Panorama and set it up as "vm-panorama".

2) Open your project again, go to plugins and create a new log connector, in this case you should be able to select the device, the source file and the DG but also selecting the FWs. See attached screenshot for reference.

 

dpuigdomenec_0-1714035781709.png

Hope this helps,

David

 

 

L0 Member

Thank you David, that did the trick!

  • 1 accepted solution
  • 1944 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!