This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Hey,
strange. Have you checked the date, time and time zone on the firewall and expedition?
To rule out a malfunction in the GUI, would I test it all over the CLI. Is there the problem too?
Have you also checked the maximum number of lines in the CSV file? How many lines does your file have?
Please check the configuration as described in the link.
_https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaPCAS
Best
MatzePeng
... View more
Hi Ramzee,
logs can be exported using filters.
Palo Alto knowledgebase
_https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clj3CAC
Best
... View more
Hi Ramzee,
If I understood your question correctly, the answer is yes.
You can export the logs and the configuration from firewall to file and manually load them into expedition for analysis.
We load the files via SCP (SSH) in data folder to expedition. After that, the files are available in expedition.
The only problem we had where files that were too big ( export 24h traffic log with more than 4 GB Data fom 3000 Series Palo an more than 1 Mio lines per *.csv file). There seems to be a problem in expedition. Maybe our system need more perfomance. Don't know at the moment.
Would make sense to test it with short files at the beginning.
I think all the information you need can be found in the documentation above.
Best
MatzePeng
... View more
Hey community,
when we should expect the documentation "Using Machine Learning to create Policies from logs" ?
We have implemented expedition in the latest version .
Add new Project and load firewall config's and Logg's works fine so far.
But if the firewall export files are loaded from 24 hours with more than 4 GB size, the tool will stop working. How do you best deal with the shortage of data? Is it possible to send the data directly via syslogg to expedition?
How is this set up?
Thanks
MatzePeng
... View more