Device > Setup > Telemetry
Telemetry is the process of collecting and transmitting data for threat and support
analysis, and to enable application logic. To collect and transmit telemetry to
Palo Alto Networks, you must first select a destination region. If your organization
currently has a Strata Logging Service license, then your destination region is limited to
the region where your Strata Logging Service instance resides.
Telemetry data is used to power applications that increase your ability to manage and
configure your Palo Alto Networks products and services. These apps offer you improved
visibility into device health, performance, capacity planning, and configuration. Palo Alto
Networks also continually uses this data to improve threat prevention, and to help you
maximize your product usage benefits.
Select to see the
currently collected telemetry categories. To change these categories, edit the Telemetry
widget. Deselect any categories that you don't want the firewall to collect, and commit your change.
Generate Telemetry File to obtain a live example of the data that
the firewall will send to Palo Alto Networks at the next
telemetry transmission interval.
To disable telemetry transmission entirely, make sure Enable Telemetry is not checked, and commit your change.
Telemetry Autoenablement
Beginning with PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and later releases, the
telemetry autoenablement feature configures telemetry to be enabled by default on your
devices. When you onboard a new device, telemetry is automatically enabled. Its settings are
centrally managed through Strata Cloud Manager, rather than on individual devices. This
centralized method ensures uniform telemetry settings across your entire environment.
Metrics are streamed automatically to your data residency region, removing the need for
manual setup.
You can view the read-only telemetry status and tiers by navigating to . There are two tiers:
Diagnostic tier provides essential information to determine system
operational status and pinpoint immediate causes of system failures.
Full tier provides specialized, granular, and feature-rich capabilities that
expand upon the Diagnostic tier.