- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-14-2022 04:48 PM
Hi,
We have a new deployment of Panorama using Datalake storage.
Log data from the firewalls is successfully coming through to Panorama, however, there is no "Apps Seen" or info shown for apps under Policy Optimizer.
Rule Usage data is available, and the app data is shown correctly on the local firewalls.
Setup > Management > Policy Rulebase Settings > Policy Application Usage is ticked on the firewalls and on Panorama.
Any ideas before I log it with TAC?
Thanks,
Shannon
12-20-2022 06:01 AM
Did you check if all ports between the firewalls and panorama are open in the right direction? https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/reference-port-nu...
You may try to restart panorama to see if that 'jiggles' anything loose
12-20-2022 05:23 PM
Hey - thanks for the response. I think this is resolved (has proved stable a couple of days now). What seemed to jiggle it lose was enable the free version of AI Ops on the firewalls. Not sure how that is related, or even if that is just a coincidence.
12-20-2022 08:14 PM
Did you ensure that the device certificates were all setup and working properly when you configured the firewalls? That's the one thing within AI Ops onboarding that would cause data ingestion issues if it wasn't working properly as far as I'm aware.
12-21-2022 10:44 AM
Hey yes - device certs were all good and logs were being successfully sent to CDL, and retrieved from CDL by Panorama.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!