- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-14-2022 08:34 AM
Hi all,
This is my first time attempting rule-enrichment on expedition. I followed the LIVEcommunity youtube videos for instructions. Logs exporting from the firewall for the last 90 days, and have already processed the logs. I have now enabled RE monitoring on a security policy, and when I got to RE discovery, the analyze data button brings up a log connector window. I can select the device here, but nothing else. Could somebody please let me know what steps I'm missing?
This first time I tried it, there was an xml file on the source dropdown, but it is no longer an option.
11-14-2022 08:42 AM
@Joshua-Nezat If your config is panorama config, you will add panorama device in the device tab and click "show all device " on the top right corner. find the firewalls that have logs, and process the logs there. Then you will need to select panorama device and select the specific device group that contain the firewalls that you have processed the logs.
11-14-2022 09:22 AM
Thanks for your recommendation, but I do not have a panorama in this deployment. These firewalls are managed locally. Does that change anything?
11-14-2022 09:42 AM
If your config is in firewall, you can use firewall as log connector, just select the firewall device and the config in the source, vsys1 in virtual system field, assume this is a single vsys firewall.
11-14-2022 11:42 AM
Okay I think I understand. The problem is, I am not able to select the firewall device config in the source field. The source drop-down menu (circled in blue below) gives me no options to select.
11-14-2022 12:41 PM
So I deleted the project, rebooted expedition, created new project, reimported device config, selected policy for rule enrichment monitoring, and now I have an option for the source.
After clicking save, it takes me back to the rule enrichment window, but nothing has changed. It still says "no devices in the logConnector" at the bottom of the window.
11-15-2022 01:24 PM
You might want to delete the device and re-add the firewall, retrieve the running config again.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!