Starting with PAN-OS 9.0 there is the ability to assign specific agent configurations based on software and app settings on GlobalProtect portal configuration.
It's possible to collect registry data from Windows endpoints under the new tab "Portal Data Collection".
Now my question. Is it possible to see somewhere in the logs what data was collected on the endpoints?
The data in the OPSWAT logs that are in the library are usually not intended for customer access.
Any of the data that you can see is in the report from GP client, and you can also see the report on the firewall.
However I don't understand your first answer then. I asked where can I see the data collected from "Portal Data Collection" and you said on OPSWAT logs. But without access it's not possible.
That means I have to use HIP to collect data and then I can access it in the HIP logs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!