No "Apps Seen" / Policy Optimizer data on Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

No "Apps Seen" / Policy Optimizer data on Panorama

L3 Networker

Hi,

We have a new deployment of Panorama using Datalake storage.

Log data from the firewalls is successfully coming through to Panorama, however, there is no "Apps Seen" or info shown for apps under Policy Optimizer.

Rule Usage data is available, and the app data is shown correctly on the local firewalls.

Setup > Management > Policy Rulebase Settings > Policy Application Usage is ticked on the firewalls and on Panorama.

Any ideas before I log it with TAC?

Thanks,

Shannon

 

4 REPLIES 4

Cyber Elite
Cyber Elite

Did you check if all ports between the firewalls and panorama are open in the right direction? https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/reference-port-nu...

 

You may try to restart panorama to see if that 'jiggles' anything loose

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hey - thanks for the response. I think this is resolved (has proved stable a couple of days now). What seemed to jiggle it lose was enable the free version of AI Ops on the firewalls. Not sure how that is related, or even if that is just a coincidence.

@SARowe_NZ,

Did you ensure that the device certificates were all setup and working properly when you configured the firewalls? That's the one thing within AI Ops onboarding that would cause data ingestion issues if it wasn't working properly as far as I'm aware. 

Hey yes - device certs were all good and logs were being successfully sent to CDL, and retrieved from CDL by Panorama.

  • 3056 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!