Panorama Reports Based on Device Serial Numbers not Working with Summary Database
Resolution
Issue
Custom Panorama reports based on device serial numbers generate empty reports when using the summary database.
Details
A custom report was configured (under Monitor > Manage Custom Reports) to display the top 10 traffic among two Palo Alto Networks firewalls (fw1 and fw2). The database used was the Panorama Traffic Log:
This report displayed the following results:
The database was then changed to use Panorama Traffic Summary, as generating reports using the Panorama Traffic Log database can take a longer time:
However, running the report using the Panorama Traffic Summary database, resulted in "No Matching Records":
Cause
The reason behind this behavior is that for the Panorama Traffic Summary database, the serial number of the individual firewalls are changed to the serial number of Panorama (log-collector).
Resolution
- Change the serial number in the query of the custom report, as shown below:
- Run the report and review the results:
owner: rvanderveken