Panorama Devices Test

Tracking the devices connected to the Palo Alto Panorama indicates the current load on the target panorama. Based on this information, administrators can determine if there is excessive consumption of resources or any spam/virus attack on the Palo Alto Panorama. This is exactly what the Panorama Devices test enables administrators to perform. This test reports the number of devices currently connected to Palo Alto Panorama and also reveals the names of the connected devices that are connected/disconnected to/from the panorama. If a user complains that he/she is unable to access some applications, then administrators can use this information to quickly determine whether there are too many devices connected to the target panorama. Using the same information, administrators can also determine whether there are any probable attacks on the panorama.

Target of the test: Palo Alto Panorama

Agent deploying the test: A Remote Agent

Outputs of the test: One set of results for Palo Alto Panorama that is being monitored.

Configurable parameters for the test

Parameter

Description

Test period

How often should the test be executed.

Host

The IP address of the target host to be monitored.

Port

Specify the port at which the specified host listens to.

API Key

The eG agent collects the required metrics from the target Palo Alto Panorama by executing API commands using XML API and pulls out critical metrics. In order to collect metrics, the eG agent should be provided with a valid API key.

SSL

By default, this flag is set to Yes indicating that the SSL (Secured Socket Layer) is used to connect to the target Palo Alto Panorama. If not so, set the SSL flag to No .

Detailed Diagnosis

To make diagnosis more efficient and accurate, the eG Enterprise embeds an optional detailed diagnostic capability. With this capability, the eG agents can be configured to run detailed, more elaborate tests as and when specific problems are detected. To enable the detailed diagnosis capability of this test for a particular server, choose the On option. To disable the capability, click on the Off option.

The option to selectively enable/disable the detailed diagnosis capability will be available only if the following conditions are fulfilled:

  • The eG manager license should allow the detailed diagnosis capability
  • Both the normal and abnormal frequencies configured for the detailed diagnosis measures should not be 0.
Measurements made by the test

Measurement

Description

Measurement Unit

Interpretation

Devices currently logged in

Indicates the number of devices connected to the panorama.

Number

Use the detailed diagnosis of this measure to view the name of the device that had currently logged in.

New devices

Indicates the number of devices that were newly connected to the panorama.

Number

An abnormally high value for this measure could indicate a probable virus or spam attack to this device.

Recently disconnected devices

Indicates the number of devices that were recently disconnected from the panorama.

Number

Too many disconnected devices could possibly indicate excessive consumption of the device resources.