Robuea
Enthusiast
Enthusiast

Palo-Alto Networks PAN-OS Content Pack Slow.

Jump to solution

Hi,

I'm trialling a vRealize Log Insight 4 deployment and have configured a POC environment which is ingesting very little data (approx 150 messages per second) from 8 ESXi hosts and a Palo Alto firewall.

The vRealize appliance was deployed with 8 vCPU's and 32GB vRAM.  I can't remember if this was a medium or large deployment.

Anyway, the problem I'm having is that when trying to get the Palo-Alto dashboards to display >5 mins of data, they take ages to render.  Even the 5 mins data dashboards take a few minutes to render.

There are <10 firewall events in total in the log insight database, but it is currently using all 8 vCPU's at 100% trying to render the dashboard each time.  So far it has taken 20 minutes to render a 24 hour dashboard and it still isn't finished.

unfortunately, I cant log a support call as usual as its a trial installation.  However, we're unlike to spend much further time trialling this product if we can't get it working.

For information, the other vSphere specific dashboards are working perfectly and quickly.

anyone have anything I can try before I approach my account manager?

Regards,
Rob.

0 Kudos
1 Solution

Accepted Solutions
admin
Immortal
Immortal

Hello,

Unfortunately you have picked a content pack with known performance issues. If you look at the extracted field definitions in the content pack it will give you an idea of why the queries are slow, its due to the complex regexes. Unfortunately PAN OS has not updated the content pack in over a year and therefore do not take advantage of the features we put in ; in the content pack area to improve query performance.

Hope this helps.

View solution in original post

0 Kudos
2 Replies
admin
Immortal
Immortal

Hello,

Unfortunately you have picked a content pack with known performance issues. If you look at the extracted field definitions in the content pack it will give you an idea of why the queries are slow, its due to the complex regexes. Unfortunately PAN OS has not updated the content pack in over a year and therefore do not take advantage of the features we put in ; in the content pack area to improve query performance.

Hope this helps.

0 Kudos
Robuea
Enthusiast
Enthusiast

I'll hold off on this content pack then to see if they update it.

Many thanks for your reply.

0 Kudos