10-17-2018 06:04 AM
Hi all,
I sucessfully exported the logs from my PA200 (currently on release 7.1.16) via SCP to the PALogs folder.
Expedition can find the files but when I do the "Process Files" I get the dreaded "No supported files to process". Can I get an hint on what am I doing wrong here?
10-17-2018 06:42 AM
Got it. permissions on the folder !
same issue as this: https://live.paloaltonetworks.com/t5/Expedition-Discussions/Expedition-csv-logs-stuck-in-pending/m-p...
10-17-2018 06:42 AM
Got it. permissions on the folder !
same issue as this: https://live.paloaltonetworks.com/t5/Expedition-Discussions/Expedition-csv-logs-stuck-in-pending/m-p...
10-23-2018 03:16 AM
Hey @Bruno_Alipio
How did you manage to resolve this? We are facing the same thing?
the ML temp folder is owned by www-data, same with the PALogs folder but we're still having the issue of "no supported files to process"
10-23-2018 06:38 AM
Hi @LukeBullimore,
Im not facing the issue anymore. I have my directory structure /PALogs/PaloAltoSCP owned by "expediton" and everything is running ok now.
For the first "process files" I had to change the owner to www-data:www-data but after that reverted back to expedition:expedition (to let the NGFW device export the logs directly via SCP) and everything is running fine. I now can have the new exports on this directory, have expedition finding them and processing without issues.
Hope this helps.
10-23-2018 08:08 AM
Hey @Bruno_Alipio
Thanks for your response!
In our particular issue, this was failing because a lot of our logs included IPv6 and Expedition does not currently support IPv6 for ML. Many thanks to Albert for looking at it with us 🙂
Cheers,
Luke.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!