Insufficient Data

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Insufficient Data

L0 Member

I am running into an issue where an internal application is not being identified and on the logs appear as "insufficient data". What can I do to on the firewall to allow the application to be identified? 

3 REPLIES 3

Community Team Member

Hi @flipjg33 ,

 

There are plenty of discussions on the topic. 

 

Is it a known application ?

You could try grabbing PCAP and create a custom application.

https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-insufficient-data/m-p/63535#M3...

 

KB articles on insufficient data:

Not-Applicable, Incomplete, Insufficient Data in the Application Field

Packet Capture Behavior for Unknown-TCP or Insufficient Data in Traffic Logs

 

Kind regards,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L0 Member

Check firewall rules, enable logging, and define custom app signatures.

Cyber Elite
Cyber Elite

Hello,

In my experience its something causing the tcp 3-way handshake to fail. The firewall needs a few packets to determine the application so a failure of the tcp handshake is usually the cause. Check routing and ensure you have security policies to allow the traffic. The logs should tell you if/where the traffic is allowed/blocked.

 

Regards,

  • 219 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!