I have an issue using the ML learning part of Expedition tool.
Spark dependencies: 0.1.1
Best Practices: 3.6.3
1) I have uploaded some logs in the past and was able to process them. This is all in a lab environment, and those logs are no longer relevant. Is there a way to remove these processed log files?
2) I have now uploaded new logs. But when I try to process them -> it gives me an error: "No supported files to process". Any idea how to fix this?
The only option to delete already processed logs (converted to parquet) is to delete the Temporary Data Structure that is present in the ML Settings tab.
However, this will delete all the processed data.
Internally, this actually deletes a folder (and the files inside) called connections.parquet, that it is present in your Temporary Data Structure path. You could backup that folder if you wish.
The second question seems to be a bug to me. You actually have a file in the list that can be processed. Therefore, there should not be such a problem processing that file.
Could you contact us at fwmigrate at paloaltonetworks dot com to check additional debug messages?
Try updating to the latest version to make sure it is not resolved in that one.
Also make sure that it is a complete and not malformed CSV file, so it can understand the internal format of the data and identifies the fields that PANOS 8.1 would report.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!