ML gets stuck at "Ready"

Reply
Highlighted
L1 Bithead

ML gets stuck at "Ready"

Hello all,

 

i'm trying to use ML but for some reason i cannot process the data. I've managed to export the data to the Expedition but as you can see the process option is not available. Any idea ?

 

drwxrwxr-x 2 www-data www-data 4096 Jun 25 11:38 data

drwxrwxrwx 2 expedition expedition 4096 Jul 20 12:32 logs

 

Expedition.png

Highlighted
L3 Networker

Can you please send a screenshot of the folder permissions where these log files live (via CLI)? Expedition may not have the proper permissions to parse these files.

Highlighted
L1 Bithead

Expedition.png

I have described it in my original post. I have using 2 folder - logs & data

Highlighted
L3 Networker

The folder that stores these logs requires privs to make the changes after these ML logs have been parsed. You will need to change folder permissions to achieve this.

 

sudo chown -R www-data:expedition ./logs

 

Once that is done all new logs brought into this folder should have the proper permissions to be parsed and either "deleted" or "compressed". Also the existing files more than likely were also saved wrong so you will need to make the proper file permissions and rerun it.

Highlighted
L1 Bithead

drwxrwxrwx 2 www-data expedition 4096 Jul 20 23:15 logs

 

I have changed folder permissions and i've added there new log file. Nothing changed.  

Highlighted
L3 Networker

The new log file that was imported shows the same ownership "www-data:expedition"?

Highlighted
L1 Bithead

it's weird, because some logs are correct but new ones from yesterday are still expedition:expedition

 

-rw-rw-r-- 1 www-data expedition 1141518509 Jul 20 16:49 xyz.csv
-rw-rw-r-- 1 expedition expedition 1394700274 Jul 21 16:53 xyz.csv

i cannot process both

 

Highlighted
L3 Networker

If this is in relation to your other forum post then you will need to follow what Didac mentioned.

 

https://live.paloaltonetworks.com/t5/expedition-discussions/ml-gets-stuck-at-quot-pending-quot/td-p/...

 

Yes, to answer your question on page 3 you will need to add the firewall in separately.

Highlighted
L1 Bithead

not i can see that the folder logs has following permissions - drwxrwxrwx 2 www-data expedition 4096 Jul 27 12:14 logs, but the new logs has are still  " -rw-rw-r-- 1 expedition expedition xzy.csv "

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!