Rule enrichment help

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Rule enrichment help

L1 Bithead

Hi all,

 

This is my first time attempting rule-enrichment on expedition.  I followed the LIVEcommunity youtube videos for instructions. Logs exporting from the firewall for the last 90 days, and have already processed the logs. I have now enabled RE monitoring on a security policy, and when I got to RE discovery, the analyze data button brings up a log connector window. I can select the device here, but nothing else. Could somebody please let me know what steps I'm missing?

 

This first time I tried it, there was an xml file on the source dropdown, but it is no longer an option.

 

 

JoshuaNezat_3-1668443506073.png

 

 

JoshuaNezat_2-1668443431817.png

 

 

JoshuaNezat_1-1668443300252.png

 

 

JoshuaNezat_0-1668443247073.png

 

6 REPLIES 6

L6 Presenter

@Joshua-Nezat If your config is panorama config, you will add panorama device in the device tab and click "show all device " on the top right corner. find the firewalls that have logs, and process the logs there. Then you will need to select panorama device and select the specific device group that contain the firewalls that you have processed the logs. 

Thanks for your recommendation, but I do not have a panorama in this deployment. These firewalls are managed locally. Does that change anything?

If your config is in firewall, you can use firewall as log connector, just select the firewall device and the config in the source, vsys1 in virtual system field, assume this is a single vsys firewall. 

Okay I think I understand. The problem is, I am not able to select the firewall device config in the source field. The source drop-down menu (circled in blue below) gives me no options to select.

 

JoshuaNezat_0-1668454843505.png

 

So I deleted the project, rebooted expedition, created new project, reimported device config, selected policy for rule enrichment monitoring, and now I have an option for the source.

JoshuaNezat_0-1668458321191.png

 

After clicking save, it takes me back to the rule enrichment window, but nothing has changed. It still says "no devices in the logConnector" at the bottom of the window.

 

JoshuaNezat_1-1668458491708.png

 

You might want to delete the device and re-add the firewall, retrieve the running config again. 

  • 1770 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!