Direct Query of PA-7000 Series Firewalls from Panorama
Learn how to directly query managed PA-7000 Series firewalls from Panorama without enabling log forwarding.
Because of the new support for PA-7000 Series Firewall Log Forwarding to Panorama, Panorama no longer treats the PA-7000 Series firewalls it manages as Log Collectors. If you have not configured the PA-7000 Series firewalls to forward logs to Panorama, all logs a managed PA-7000 Series firewall generates are only viewable from the local firewall and not from Panorama. Beginning with PAN-OS 8.0.8, if you do not yet have a log forwarding infrastructure that is capable of handling the logging rate and volume from the PA-7000 Series firewalls, you can now enable Panorama to directly query PA-7000 Series firewalls when monitoring logs.
To use this new capability, both the PA-7000 Series firewalls and Panorama must be running PAN-OS 8.0.8 or a later release.
With this new functionality available in PAN-OS 8.0.8 and later releases, Panorama now provides two options for monitoring logs and running reports for managed PA-7000 Series firewalls:
- (New) Enable Panorama to directly query
managed PA-7000 Series firewalls when monitoring logs.To enable Panorama to directly query the PA-7000 Series firewalls without requiring the firewalls to forward logs, you must enter the following command from the Panorama CLI:
admin@panorama> debug reportd send-request-to-7k yesAfter running the command, you will be able to view logs for managed PA-7000 Series firewalls on the Panorama Monitor tab. Additionally, as with all managed devices, you can also generate reports that include PA-7000 Series log data by selecting Remote Device Data as the Data Source.
- Configure the managed PA-7000
Series firewalls to forward logs to Panorama.Before enabling your PA-7000 Series firewalls to forward logs to Panorama, make sure you have a logging infrastructure that will handle the logging rate and volume. Refer to the table in Panorama Models to determine if you have the right logging capacity. Additionally, if you have enabled Panorama to directly query PA-7000 Series firewalls, you must disable this before you enable log forwarding by entering the following command from the Panorama CLI:
> debug reportd send-request-to-7k noAfter you have enabled your PA-7000 Series firewalls to forward logs to Panorama, the PA-7000 Series log data will be aggregated within all Panorama views: Application Command Center (ACC), the App-Scope, the log viewer (Monitor tab), and the standard, customizable reporting options on Panorama.
Panorama Features Traps Log Ingestion on Panorama Extended Support for Multiple Panorama Interfaces Streamlined Deployment of Software and Content Updates from Panorama Logging Enhancements on ...
PA-7000 Series Firewall Log Forwarding to Panorama
PA-7000 Series Firewall Log Forwarding to Panorama You can now forward logs from PA-7000 Series firewalls to Panorama for improved log retention, which helps you ...
Configure Log Forwarding to Panorama
Configure Log Forwarding to Panorama Each firewall stores its log files locally by default and cannot display the logs that reside on other firewalls. Therefore, ...
Management Changes PAN-OS® 8.0 has the following changes in default behavior for firewall and Panorama™ management features: Feature Change Log Forwarding ( PAN-OS 8.0.6 and ...
Objects > Log Forwarding
Objects > Log Forwarding By default, the logs that the firewall generates reside only in its local storage. However, if you want to use Panorama, ...
Panorama Features New Panorama Features Description Direct Query of PA-7000 Series Firewalls from Panorama ( PAN-OS 8.0.8 and later releases ) With the new support ...
Management Features PA-7000 Series Firewall Log Forwarding to Panorama NetFlow Support for PA-7000 Series Firewalls Action-Oriented Log Forwarding using HTTP Selective Log Forwarding Based on ...
Management Features PAN-OS 8.0.5 introduces support for the Logging Service . New Management Features Description Administrator-Level Commit and Revert You can now commit, validate, preview, ...