Prisma Cloud Network traffic Accepted field value is not captured correctly in the downloaded csv report

Prisma Cloud Network traffic Accepted field value is not captured correctly in the downloaded csv report

8454
Created On 04/25/19 20:14 PM - Last Modified 12/13/19 22:36 PM


Symptom


  1. Run the following example RQL in Investigate tab:
network where source.publicnetwork IN ( 'Suspicious IPs', 'Internet IPs' ) AND dest.port IN ( 11211 ) 
  1. From the resulting network diagram, click on a traffic line to a resource. On the right side, note the value YES for the field Accepted traffic.
Internet IPs → TestLB

Bytes Accepted
1.7 kB
Bytes Attempted
0 B
 
PORTTRAFFIC VOLUMEACCEPTED
112111.7 kBYes
  1. Download the report by clicking on the download icon on the Investigate page.
  2. Note the value for Accepted field reported as 'NO'. 
Source NameSource IPDestination NameDestination IPDestination PortClassificationAcceptedInbound BytesOutbound BytesTotal BytesInbound PacketsOutbound PacketsTotal PacketsClassified as Suspicious onReason for Suspicious Classification
Parfumuri Femei.com SRL0.0.0.0TestLB172.31.59.12111211unavailableno1760017604000    

Note: All values show No for Accepted traffic in csv, irrespective of the value in the network diagram


Environment


Prisma Cloud console

Cause


Defect.

Resolution


Defect being worked by Engineering.
Please use the network diagram information at this time, not the csv report.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLmdCAG&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language