Tenant receiving EAL , traffic logs with device profiling

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Tenant receiving EAL , traffic logs with device profiling

L1 Bithead

hello,

 

we onboarded IOT license on PA-400 series , we configured the tenant properly and we associated the device.

 

we enabled service edge ( green status ) and we enabled EAL logging , cloud logging ( in cortex data lake tab ) .

 

on the zones we enabled device identification, on the security policies we enabled logging with Enhanced application logging .

 

the tenant is receiving logs normally and there is pulling requests on the tenant for 3 consecutive days , but the tenant is not showing any device on it.

 

what can be the problem? If someone can help 

 

thank you!

1 REPLY 1

L0 Member

This is a tricky issue, but let's break down the troubleshooting steps for why your Palo Alto PA-400 with IoT license isn't showing devices in the tenant, even though logs are being received and everything seems configured correctly.

Possible Causes and Troubleshooting Steps:

Device Identification Configuration Issues:

Zone Configuration:
Double-check that device identification is enabled on the correct zones where your IoT devices are communicating. Ensure that the IoT traffic is actually passing through these zones.
Verify that the zones are configured for the correct network segments where the IoT devices reside.
Policy Configuration:
Ensure that the security policies allowing IoT traffic also have device identification enabled.
Confirm that the policies are applied in the correct order.
Application Filters:
If you're using application filters in your policies, ensure they are not inadvertently blocking the traffic needed for device identification.
Log Forwarding Profiles:
Confirm that the log forwarding profile attached to the security policy has the correct log types selected. Device ID logs must be forwarded.

 

  • 140 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!