Different data in ACC reports and custome created report

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Different data in ACC reports and custome created report

L1 Bithead

Helo Everybody,

I have created a custom report in Panorama to generate the same data that we get in ACC - Application usage report, for last one month. But it looks like the data in the custom report is always different than that which is genereated in acc widget/report.

4 REPLIES 4

Community Team Member

Hi @rubber_ducky ,

 

On which platform and OS are you seeing this ?

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L1 Bithead

Panorama - sosftware version 9.1.5

Community Team Member

Hi @rubber_ducky ,

 

Have you tried comparing these results over a shorter period of time ? The problem with ACC is that there's a limitation of 100K lines and it might not contain the full amount of data.

 

When you query ACC stats for a month, the result is generated by aggregating weekly, daily and hourly summary databases.  There is however a limit imposed on this aggregation ... which is 100k lines.  So once the limit is reached the report might not contain all the data:

Check this link for details:

ACC is Not Accurate During Heavy Traffic Log Generation 

 

That being said, I would also recommend upgrading your OS version to 9.1.10 which is the preferred release at the moment of me writing this... just to rule out possible bugs that might have been resolved in newer OS versions :

 

PAN-OS Software Release Guidance 

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L1 Bithead

Thank you for the response.

So do you mean that the custom report data is more accurate. I had filtered for 5 June 12 AM - 5 July 12 AM in ACC. Can I conider the custom report info to be more accurate and continue to use that. Also in ACC widget, it shows the top 10 and then "others" which has the rest of the applications which I can see when I maxmize the widget.

The requirement was just the top 10 so I had generated the custome report for only top 10 applications and for same time frame like I used in ACC, 5 June 12 AM - 5 July 12 AM.

 

  • 3311 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!