Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingHard
A network security analyst is troubleshooting why a specific custom report is not generating data. They have confirmed the report query is correct and the time range covers relevant events. What is a common reason for a custom report to show no data even with a correct query and time range?
- AThe security policies are not configured to log the events targeted by the report.
- BThe ACC widgets are consuming all available log data.
- CThe firewall clock is out of sync with the reporting server.
- DThe firewall has run out of disk space for report generation.
Show answer & explanationAnswer & explanation
Correct answer: A. The security policies are not configured to log the events targeted by the report.
For any event to appear in logs and subsequently in reports, the security policies must be explicitly configured to log those events. If the 'Log at Session End' or 'Log at Session Start' options are not enabled on the relevant security rules, no logs will be generated, and thus no data will appear in reports.
Why the other options are wrong
- B. ACC widgets display data from existing logs; they do not 'consume' or prevent logs from being generated for reports.
- C. While clock sync is important, it usually results in time discrepancies, not a complete lack of data if logs are being generated.
- D. Running out of disk space would prevent *all* new logs/reports, not just a specific report, and would typically be indicated by system alerts.
Palo Alto Security Policy Logging
Palo Alto Networks security policies must be configured with logging enabled ('Log at Session Start' or 'Log at Session End') to generate log entries for matching traffic. Without this, no data will be available for monitoring, reporting, or alerting.
- Logging is disabled by default on the implicit 'deny' rule.
- Crucial for visibility into network traffic and security events.
- Different log types (Traffic, Threat, URL Filtering) are generated based on profiles applied to policies.
Memory trick: No logs, no data; check the policy first.