We have multiple Paloalto firewalls running in version 10.1.X/10.2. None of them are showing the source or destination mac address in the traffic logs. When we select the source/destination mac address column in the traffic logs, it shows blank.
So how to display the source/destination mac address in the traffic logs
Hello there. The Source Device MAC column and the Destination Device Mac Columns are used in IoT security, to know what types of devices (printers, cameras, thermostats, Alexas, etc) are in the network. It is not designed to capture mac addresses. To do this, you would need to confirm you have purchased an IoT license and also deployed IoT, using Tap mode, Syslog, DHCP Relay Agent, or similar functionality to obtain the mac addresses.
What other questions may I answer for you?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!