In PAN-OS 9.1 and earlier, the firewall
used the Palo Alto Networks Services service route to send Enhanced
Application Logs (EAL logs). In PAN-OS 10.0 and later versions,
the firewall sends EAL logs using the Data Services service route,
which uses the management interface by default. Other services,
such as Data Loss Prevention (DLP), also use this service route. You
can configure any Layer 3 (L3) interface, including the management
or dataplane interfaces, for the service route. If your firewall
currently sends EAL logs (for example, if you are using Cortex XDR),
the firewall automatically uses the Data Services service route after
you upgrade to PAN-OS 10.0. If you want to use a different interface
for the service route, you can change the service route to any L3 interface. If
you use a log forwarding card (LFC) with the 7000 series, when you
upgrade to PAN-OS 10.0, you must configure the management plane
or dataplane interface for the service route because the LFC ports
do not support the requirements for the service route. We recommend
using the dataplane interface for the Data Services service route. |