How to Use an ACC Query to Identify Traffic Volume and Export the Query to a Monitor Log

How to Use an ACC Query to Identify Traffic Volume and Export the Query to a Monitor Log

25599
Created On 07/14/20 16:18 PM - Last Modified 01/09/25 08:10 AM


Objective


To show customers how the queries from the ACC tab can be exported to the Monitor Logs to generate useful log file submissions for various Threat and Firewall related case.



Environment


  • PAN-OS 8.1
  • PAN-OS 9.0
  • PAN-OS 9.1
  • PAN-OS 10.*
  • PAN-OS 11.*
  • Admin Roles with permission to the ACC and Monitor tabs


Procedure


1. Click on the ACC tab.

Select the ACC tab.

2. Select the "Time" drop-down arrow and select the time frame that the threat was noticed.

Modify the time period to when the threat occurred

3. Click on the Threat Activity tab.

Select the Threat Activity tab to see the threats that were noticed during the specified time period.

4. Click on either the Threat Name or the Threat ID to place it in the local query

Select either the Threat Name or the Threat ID that you want to be the scope of your query.

5. In the upper right corner of the Threat Activity window, there are 4 icons. Select the square with 3 lines on it. This is the "Jump To Logs" option. Select the Threat Log menu item.

Select the Jump to Logs icon and select the Threat Logs option to export the query to the Threat Logs.

How to Export the ACC Report

Click on the export option which is highlighted and a PDF file will be generated and will be downloaded to the local user PC.


6. The query is automatically formatted within the Threat Log. This is useful log information that can now be exported to a CSV file and uploaded to a case for analysis.

The query from the ACC is now properly formatted in the Threat Log producing log entries that can be exported for analysis.
 



Additional Information


Within the Learning Center, there is an ACC Demo video showing this process step by step.
 

  • Optimizing Firewall Threat Prevention (EDU-114)
    • Viewing Threat and Traffic Information
      • Application Command Center (ACC) - Demo
User-added image


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UqqCAE&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language