1. Home
Location
    Techdocs Logo Techdocs Logo
    • Documentation Home
    • Palo Alto Networks
    • Support
    • Live Community
    • Knowledge Base
    1. Home
    2. Panorama
    3. Panorama Administrator's Guide
    4. Manage Log Collection
    5. Verify Log Forwarding to Panorama
    Download PDF
    Last Updated:
    Jul 23, 2022
    Current Version:
    10.0 (EoL)
    • Version 11.0
    • Version 10.2
    • Version 10.1
    • Version 10.0 (EoL)
    • Version 9.1
    End-of-Life (EoL)

    Table of Contents


    Filter icon
    Filter
    Panorama Overview
    About Panorama
    Panorama Models
    Centralized Firewall Configuration and Update Management
    Context Switch—Firewall or Panorama
    Total Configuration Size for Panorama
    Templates and Template Stacks
    Device Groups
    Device Group Hierarchy
    Device Group Policies
    Device Group Objects
    Centralized Logging and Reporting
    Managed Collectors and Collector Groups
    Local and Distributed Log Collection
    Caveats for a Collector Group with Multiple Log Collectors
    Log Forwarding Options
    Centralized Reporting
    Data Redistribution Using Panorama
    Role-Based Access Control
    Administrative Roles
    Authentication Profiles and Sequences
    Access Domains
    Administrative Authentication
    Panorama Commit, Validation, and Preview Operations
    Plan Your Panorama Deployment
    Deploy Panorama: Task Overview
    Set Up Panorama
    Determine Panorama Log Storage Requirements
    Manage Large-Scale Firewall Deployments
    Determine the Optimal Large-Scale Firewall Deployment Solution
    Increased Device Management Capacity for M-600 and Panorama Virtual Appliance
    Increased Device Management Capacity Requirements
    Deploy Panorama for Increased Device Management
    Install Panorama for Increased Device Management Capacity
    Upgrade Panorama for Increased Device Management Capacity
    Set Up the Panorama Virtual Appliance
    Setup Prerequisites for the Panorama Virtual Appliance
    Install the Panorama Virtual Appliance
    Install Panorama on VMware
    Install Panorama on an ESXi Server
    Install Panorama on vCloud Air
    Support for VMware Tools on the Panorama Virtual Appliance
    Set Up Panorama on Alibaba Cloud
    Upload the Panorama Virtual Appliance Image to Alibaba Cloud
    Install Panorama on Alibaba Cloud
    Install Panorama on AWS
    Install Panorama on AWS GovCloud
    Install Panorama on Azure
    Install Panorama on Google Cloud Platform
    Install Panorama on Hyper-V
    Install Panorama on KVM
    Set Up Panorama on Oracle Cloud Infrastructure (OCI)
    Upload the Panorama Virtual Appliance Image to OCI
    Install Panorama on Oracle Cloud Infrastructure (OCI)
    Generate a SSH Key for Panorama on OCI
    Perform Initial Configuration of the Panorama Virtual Appliance
    Set Up The Panorama Virtual Appliance as a Log Collector
    Set Up the Panorama Virtual Appliance with Local Log Collector
    Set up a Panorama Virtual Appliance in Panorama Mode
    Set up a Panorama Virtual Appliance in Management Only Mode
    Expand Log Storage Capacity on the Panorama Virtual Appliance
    Preserve Existing Logs When Adding Storage on Panorama Virtual Appliance in Legacy Mode
    Add a Virtual Disk to Panorama on an ESXi Server
    Add a Virtual Disk to Panorama on vCloud Air
    Add a Virtual Disk to Panorama on Alibaba Cloud
    Add a Virtual Disk to Panorama on AWS
    Add a Virtual Disk to Panorama on Azure
    Add a Virtual Disk to Panorama on Google Cloud Platform
    Add a Virtual Disk to Panorama on Hyper-V
    Add a Virtual Disk to Panorama on KVM
    Add a Virtual Disk to Panorama on Oracle Cloud Infrastructure (OCI)
    Mount the Panorama ESXi Server to an NFS Datastore
    Increase CPUs and Memory on the Panorama Virtual Appliance
    Increase CPUs and Memory for Panorama on an ESXi Server
    Increase CPUs and Memory for Panorama on vCloud Air
    Increase CPUs and Memory for Panorama on Alibaba Cloud
    Increase CPUs and Memory for Panorama on AWS
    Increase CPUs and Memory for Panorama on Azure
    Increase CPUs and Memory for Panorama on Google Cloud Platform
    Increase CPUs and Memory for Panorama on Hyper-V
    Increase CPUs and Memory for Panorama on KVM
    Increase CPUs and Memory for Panorama on Oracle Cloud Infrastructure (OCI)
    Increase the System Disk on the Panorama Virtual Appliance
    Increase the System Disk for Panorama on an ESXi Server
    Increase the System Disk for Panorama on Google Cloud Platform
    Complete the Panorama Virtual Appliance Setup
    Convert Your Panorama Virtual Appliance
    Convert Your Evaluation Panorama to a Production Panorama with Local Log Collector
    Convert Your Evaluation Panorama to a Production Panorama without Local Log Collector
    Convert Your Evaluation Panorama to VM-Flex Licensing with Local Log Collector
    Convert Your Evaluation Panorama to VM-Flex Licensing without Local Log Collector
    Convert Your Production Panorama to an ELA Panorama
    Set Up the M-Series Appliance
    M-Series Appliance Interfaces
    Perform Initial Configuration of the M-Series Appliance
    M-Series Setup Overview
    Set Up an M-Series Appliance in Management Only Mode
    Set Up an M-Series Appliance in Panorama Mode
    Set Up an M-Series Appliance in Log Collector Mode
    Set Up the M-Series Appliance as a Log Collector
    Increase Storage on the M-Series Appliance
    Add Additional Drives to an M-Series Appliance
    Upgrade Drives on an M-Series Appliance
    Configure Panorama to Use Multiple Interfaces
    Multiple Interfaces for Network Segmentation Example
    Configure Panorama for Network Segmentation
    Register Panorama and Install Licenses
    Register Panorama
    Activate a Panorama Support License
    Activate/Retrieve a Firewall Management License when the Panorama Virtual Appliance is Internet-connected
    Activate/Retrieve a Firewall Management License when the Panorama Virtual Appliance is not Internet-connected
    Activate/Retrieve a Firewall Management License on the M-Series Appliance
    Install the Panorama Device Certificate
    Install Content and Software Updates for Panorama
    Panorama, Log Collector, Firewall, and WildFire Version Compatibility
    Install Updates for Panorama in an HA Configuration
    Install Updates for Panorama with an Internet Connection
    Install Updates for Panorama When Not Internet-Connected
    Install Updates Automatically for Panorama without an Internet Connection
    Migrate Panorama Logs to the New Log Format
    Transition to a Different Panorama Model
    Migrate from a Panorama Virtual Appliance to an M-Series Appliance
    Migrate a Panorama Virtual Appliance to a Different Hypervisor
    Migrate from an M-Series Appliance to a Panorama Virtual Appliance
    Migrate from an M-100 Appliance to an M-500 Appliance
    Migrate from an M-100 or M-500 Appliance to an M-200 or M-600 Appliance
    Access and Navigate Panorama Management Interfaces
    Log in to the Panorama Web Interface
    Navigate the Panorama Web Interface
    Log in to the Panorama CLI
    Set Up Administrative Access to Panorama
    Configure an Admin Role Profile
    Configure an Access Domain
    Configure Administrative Accounts and Authentication
    Configure a Panorama Administrator Account
    Configure Local or External Authentication for Panorama Administrators
    Configure a Panorama Administrator with Certificate-Based Authentication for the Web Interface
    Configure an Administrator with SSH Key-Based Authentication for the CLI
    Configure RADIUS Authentication for Panorama Administrators
    Configure TACACS+ Authentication for Panorama Administrators
    Configure SAML Authentication for Panorama Administrators
    Set Up Authentication Using Custom Certificates
    How Are SSL/TLS Connections Mutually Authenticated?
    Configure Authentication Using Custom Certificates on Panorama
    Configure Authentication Using Custom Certificates on Managed Devices
    Add New Client Devices
    Change Certificates
    Change a Server Certificate
    Change a Client Certificate
    Change a Root or Intermediate CA Certificate
    Manage Firewalls
    Add a Firewall as a Managed Device
    Install the Device Certificate for Managed Firewalls
    Install the Device Certificate for a Managed Firewall
    Install the Device Certificate for Multiple Managed Firewalls
    Set Up Zero Touch Provisioning
    ZTP Overview
    About ZTP
    ZTP Configuration Elements
    Install the ZTP Plugin
    Install the ZTP Plugin on Panorama
    Register Panorama with the ZTP Service
    Register Panorama with the ZTP Service for New Deployments
    Register Panorama with the ZTP Service for Existing Deployments
    Configure the ZTP Installer Administrator Account
    Add ZTP Firewalls to Panorama
    Add a ZTP Firewall to Panorama
    Import Multiple ZTP Firewalls to Panorama
    Use the CLI for ZTP Tasks
    Uninstall the ZTP Plugin
    Manage Device Groups
    Add a Device Group
    Create a Device Group Hierarchy
    Create Objects for Use in Shared or Device Group Policy
    Revert to Inherited Object Values
    Manage Unused Shared Objects
    Manage Precedence of Inherited Objects
    Move or Clone a Policy Rule or Object to a Different Device Group
    Push a Policy Rule to a Subset of Firewalls
    Manage the Rule Hierarchy
    Manage Templates and Template Stacks
    Template Capabilities and Exceptions
    Add a Template
    Configure a Template Stack
    Configure a Template or Template Stack Variable
    Import and Overwrite Existing Template Stack Variables
    Override a Template or Template Stack Value
    Override a Template Value on the Firewall
    Override a Template Value Using a Template Stack
    Override a Template or Template Stack Value Using Variables
    Disable/Remove Template Settings
    Manage the Master Key from Panorama
    Redistribute Data to Managed Firewalls
    Transition a Firewall to Panorama Management
    Plan the Transition to Panorama Management
    Migrate a Firewall to Panorama Management
    Migrate a Firewall HA Pair to Panorama Management
    Load a Partial Firewall Configuration into Panorama
    Localize a Panorama Pushed Configuration on a Managed Firewall
    Device Monitoring on Panorama
    Monitor Device Health
    Monitor Policy Rule Usage
    Use Case: Configure Firewalls Using Panorama
    Device Groups in this Use Case
    Templates in this Use Case
    Set Up Your Centralized Configuration and Policies
    Add the Managed Firewalls and Deploy Updates
    Use Templates to Administer a Base Configuration
    Use Device Groups to Push Policy Rules
    Preview the Rules and Commit Changes
    Manage Log Collection
    Configure a Managed Collector
    Configure Authentication for a Dedicated Log Collector
    Configure an Administrative Account for a Dedicated Log Collector
    Configure RADIUS Authentication for a Dedicated Log Collector
    Configure TACACS+ Authentication for a Dedicated Log Collector
    Configure LDAP Authentication for a Dedicated Log Collector
    Manage Collector Groups
    Configure a Collector Group
    Configure Authentication with Custom Certificates Between Log Collectors
    Move a Log Collector to a Different Collector Group
    Remove a Firewall from a Collector Group
    Configure Log Forwarding to Panorama
    Configure Syslog Forwarding to External Destinations
    Forward Logs to Cortex Data Lake
    Verify Log Forwarding to Panorama
    Modify Log Forwarding and Buffering Defaults
    Configure Log Forwarding from Panorama to External Destinations
    Log Collection Deployments
    Deploy Panorama with Dedicated Log Collectors
    Deploy Panorama M-Series Appliances with Local Log Collectors
    Deploy Panorama Virtual Appliances with Local Log Collectors
    Deploy Panorama Virtual Appliances in Legacy Mode with Local Log Collection
    Manage WildFire Appliances
    Add Standalone WildFire Appliances to Manage with Panorama
    Configure Basic WildFire Appliance Settings on Panorama
    Configure Authentication for a WildFire Appliance
    Configure An Administrative Account for a WildFire Appliance
    Configure RADIUS Authentication for a WildFire Appliance
    Configure TACACS+ Authentication for a WildFire Appliance
    Configure LDAP Authentication for a WildFire Appliance
    Set Up Authentication Using Custom Certificates on WildFire Appliances and Clusters
    Configure a Custom Certificate for a Panorama Managed WildFire Appliance
    Configure Authentication with a Single Custom Certificate for a WildFire Cluster
    Apply Custom Certificates on a WildFire Appliance Configured through Panorama
    Remove a WildFire Appliance from Panorama Management
    Manage WildFire Clusters
    Configure a Cluster Centrally on Panorama
    Configure a Cluster and Add Nodes on Panorama
    Configure General Cluster Settings on Panorama
    Configure Authentication for a WildFire Cluster
    Configure an Administrative Account for a WildFire Cluster
    Configure RADIUS Authentication for a WildFire Cluster
    Configure TACACS+ Authentication for a WildFire Cluster
    Configure LDAP Authentication for a WildFire Cluster
    Remove a Cluster from Panorama Management
    Configure Appliance-to-Appliance Encryption Using Predefined Certificates Centrally on Panorama
    Configure Appliance-to-Appliance Encryption Using Custom Certificates Centrally on Panorama
    View WildFire Cluster Status Using Panorama
    Upgrade a Cluster Centrally on Panorama with an Internet Connection
    Upgrade a Cluster Centrally on Panorama without an Internet Connection
    Manage Licenses and Updates
    Manage Licenses on Firewalls Using Panorama
    Deploy Upgrades to Firewalls, Log Collectors, and WildFire Appliances Using Panorama
    Supported Updates
    Schedule a Content Update Using Panorama
    Upgrade Log Collectors When Panorama Is Internet-Connected
    Upgrade Log Collectors When Panorama Is Not Internet-Connected
    Upgrade Firewalls When Panorama Is Internet-Connected
    Upgrade Firewalls When Panorama Is Not Internet-Connected
    Upgrade a ZTP Firewall
    Revert Content Updates from Panorama
    Monitor Network Activity
    Use Panorama for Visibility
    Monitor the Network with the ACC and AppScope
    Analyze Log Data
    Generate, Schedule, and Email Reports
    Configure Key Limits for Scheduled Reports
    Ingest Traps ESM Logs on Panorama
    Use Case: Monitor Applications Using Panorama
    Use Case: Respond to an Incident Using Panorama
    Incident Notification
    Review the Widgets in the ACC
    Review Threat Logs
    Review WildFire Logs
    Review Data Filtering Logs
    Update Security Rules
    Panorama High Availability
    Panorama HA Prerequisites
    Priority and Failover on Panorama in HA
    Failover Triggers
    HA Heartbeat Polling and Hello Messages
    HA Path Monitoring
    Logging Considerations in Panorama HA
    Logging Failover on a Panorama Virtual Appliance in Legacy Mode
    Logging Failover on an M-Series Appliance or Panorama Virtual Appliance in Panorama Mode
    Synchronization Between Panorama HA Peers
    Manage a Panorama HA Pair
    Set Up HA on Panorama
    Set Up Authentication Using Custom Certificates Between HA Peers
    Test Panorama HA Failover
    Switch Priority after Panorama Failover to Resume NFS Logging
    Restore the Primary Panorama to the Active State
    Administer Panorama
    Preview, Validate, or Commit Configuration Changes
    Enable Automated Commit Recovery
    Manage Panorama and Firewall Configuration Backups
    Schedule Export of Configuration Files
    Save and Export Panorama and Firewall Configurations
    Revert Panorama Configuration Changes
    Configure the Maximum Number of Configuration Backups on Panorama
    Load a Configuration Backup on a Managed Firewall
    Compare Changes in Panorama Configurations
    Manage Locks for Restricting Configuration Changes
    Add Custom Logos to Panorama
    Use the Panorama Task Manager
    Manage Storage Quotas and Expiration Periods for Logs and Reports
    Log and Report Storage
    Log and Report Expiration Periods
    Configure Storage Quotas and Expiration Periods for Logs and Reports
    Configure the Run Time for Panorama Reports
    Monitor Panorama
    Panorama System and Configuration Logs
    Monitor Panorama and Log Collector Statistics Using SNMP
    Reboot or Shut Down Panorama
    Configure Panorama Password Profiles and Complexity
    Panorama Plugins
    About Panorama Plugins
    Install Panorama Plugins
    VM-Series Plugin and Panorama Plugins
    Install the VM-Series Plugin on Panorama
    Troubleshooting
    Troubleshoot Panorama System Issues
    Generate Diagnostic Files for Panorama
    Diagnose Panorama Suspended State
    Monitor the File System Integrity Check
    Manage Panorama Storage for Software and Content Updates
    Recover from Split Brain in Panorama HA Deployments
    Troubleshoot Log Storage and Connection Issues
    Verify Panorama Port Usage
    Resolve Zero Log Storage for a Collector Group
    Replace a Failed Disk on an M-Series Appliance
    Replace the Virtual Disk on an ESXi Server
    Replace the Virtual Disk on vCloud Air
    Migrate Logs to a New M-Series Appliance in Log Collector Mode
    Migrate Logs to a New M-Series Appliance in Panorama Mode
    Migrate Logs to a New M-Series Appliance Model in Panorama Mode in High Availability
    Migrate Logs to the Same M-Series Appliance Model in Panorama Mode in High Availability
    Migrate Log Collectors after Failure/RMA of Non-HA Panorama
    Regenerate Metadata for M-Series Appliance RAID Pairs
    View Log Query Jobs
    Replace an RMA Firewall
    Partial Device State Generation for Firewalls
    Before Starting RMA Firewall Replacement
    Restore the Firewall Configuration after Replacement
    Troubleshoot Commit Failures
    Troubleshoot Registration or Serial Number Errors
    Troubleshoot Reporting Errors
    Troubleshoot Device Management License Errors
    Troubleshoot Automatically Reverted Firewall Configurations
    Complete Content Update When Panorama HA Peer is Down
    View Task Success or Failure Status
    Test Policy Match and Connectivity for Managed Devices
    Troubleshoot Policy Rule Traffic Match
    Troubleshoot Connectivity to Network Resources
    Downgrade from Panorama 10.0
    • Panorama Overview
      • About Panorama
      • Panorama Models
      • Centralized Firewall Configuration and Update Management
        • Context Switch—Firewall or Panorama
        • Total Configuration Size for Panorama
        • Templates and Template Stacks
        • Device Groups
          • Device Group Hierarchy
          • Device Group Policies
          • Device Group Objects
      • Centralized Logging and Reporting
        • Managed Collectors and Collector Groups
        • Local and Distributed Log Collection
        • Caveats for a Collector Group with Multiple Log Collectors
        • Log Forwarding Options
        • Centralized Reporting
      • Data Redistribution Using Panorama
      • Role-Based Access Control
        • Administrative Roles
        • Authentication Profiles and Sequences
        • Access Domains
        • Administrative Authentication
      • Panorama Commit, Validation, and Preview Operations
      • Plan Your Panorama Deployment
      • Deploy Panorama: Task Overview
    • Set Up Panorama
      • Determine Panorama Log Storage Requirements
      • Manage Large-Scale Firewall Deployments
        • Determine the Optimal Large-Scale Firewall Deployment Solution
        • Increased Device Management Capacity for M-600 and Panorama Virtual Appliance
          • Increased Device Management Capacity Requirements
          • Deploy Panorama for Increased Device Management
            • Install Panorama for Increased Device Management Capacity
            • Upgrade Panorama for Increased Device Management Capacity
      • Set Up the Panorama Virtual Appliance
        • Setup Prerequisites for the Panorama Virtual Appliance
        • Install the Panorama Virtual Appliance
          • Install Panorama on VMware
            • Install Panorama on an ESXi Server
            • Install Panorama on vCloud Air
            • Support for VMware Tools on the Panorama Virtual Appliance
          • Set Up Panorama on Alibaba Cloud
            • Upload the Panorama Virtual Appliance Image to Alibaba Cloud
            • Install Panorama on Alibaba Cloud
          • Install Panorama on AWS
          • Install Panorama on AWS GovCloud
          • Install Panorama on Azure
          • Install Panorama on Google Cloud Platform
          • Install Panorama on Hyper-V
          • Install Panorama on KVM
          • Set Up Panorama on Oracle Cloud Infrastructure (OCI)
            • Upload the Panorama Virtual Appliance Image to OCI
            • Install Panorama on Oracle Cloud Infrastructure (OCI)
            • Generate a SSH Key for Panorama on OCI
        • Perform Initial Configuration of the Panorama Virtual Appliance
        • Set Up The Panorama Virtual Appliance as a Log Collector
        • Set Up the Panorama Virtual Appliance with Local Log Collector
        • Set up a Panorama Virtual Appliance in Panorama Mode
        • Set up a Panorama Virtual Appliance in Management Only Mode
        • Expand Log Storage Capacity on the Panorama Virtual Appliance
          • Preserve Existing Logs When Adding Storage on Panorama Virtual Appliance in Legacy Mode
          • Add a Virtual Disk to Panorama on an ESXi Server
          • Add a Virtual Disk to Panorama on vCloud Air
          • Add a Virtual Disk to Panorama on Alibaba Cloud
          • Add a Virtual Disk to Panorama on AWS
          • Add a Virtual Disk to Panorama on Azure
          • Add a Virtual Disk to Panorama on Google Cloud Platform
          • Add a Virtual Disk to Panorama on Hyper-V
          • Add a Virtual Disk to Panorama on KVM
          • Add a Virtual Disk to Panorama on Oracle Cloud Infrastructure (OCI)
          • Mount the Panorama ESXi Server to an NFS Datastore
        • Increase CPUs and Memory on the Panorama Virtual Appliance
          • Increase CPUs and Memory for Panorama on an ESXi Server
          • Increase CPUs and Memory for Panorama on vCloud Air
          • Increase CPUs and Memory for Panorama on Alibaba Cloud
          • Increase CPUs and Memory for Panorama on AWS
          • Increase CPUs and Memory for Panorama on Azure
          • Increase CPUs and Memory for Panorama on Google Cloud Platform
          • Increase CPUs and Memory for Panorama on Hyper-V
          • Increase CPUs and Memory for Panorama on KVM
          • Increase CPUs and Memory for Panorama on Oracle Cloud Infrastructure (OCI)
        • Increase the System Disk on the Panorama Virtual Appliance
          • Increase the System Disk for Panorama on an ESXi Server
          • Increase the System Disk for Panorama on Google Cloud Platform
        • Complete the Panorama Virtual Appliance Setup
        • Convert Your Panorama Virtual Appliance
          • Convert Your Evaluation Panorama to a Production Panorama with Local Log Collector
          • Convert Your Evaluation Panorama to a Production Panorama without Local Log Collector
          • Convert Your Evaluation Panorama to VM-Flex Licensing with Local Log Collector
          • Convert Your Evaluation Panorama to VM-Flex Licensing without Local Log Collector
          • Convert Your Production Panorama to an ELA Panorama
      • Set Up the M-Series Appliance
        • M-Series Appliance Interfaces
        • Perform Initial Configuration of the M-Series Appliance
        • M-Series Setup Overview
          • Set Up an M-Series Appliance in Management Only Mode
          • Set Up an M-Series Appliance in Panorama Mode
          • Set Up an M-Series Appliance in Log Collector Mode
        • Set Up the M-Series Appliance as a Log Collector
        • Increase Storage on the M-Series Appliance
          • Add Additional Drives to an M-Series Appliance
          • Upgrade Drives on an M-Series Appliance
        • Configure Panorama to Use Multiple Interfaces
          • Multiple Interfaces for Network Segmentation Example
          • Configure Panorama for Network Segmentation
      • Register Panorama and Install Licenses
        • Register Panorama
        • Activate a Panorama Support License
        • Activate/Retrieve a Firewall Management License when the Panorama Virtual Appliance is Internet-connected
        • Activate/Retrieve a Firewall Management License when the Panorama Virtual Appliance is not Internet-connected
        • Activate/Retrieve a Firewall Management License on the M-Series Appliance
      • Install the Panorama Device Certificate
      • Install Content and Software Updates for Panorama
        • Panorama, Log Collector, Firewall, and WildFire Version Compatibility
        • Install Updates for Panorama in an HA Configuration
        • Install Updates for Panorama with an Internet Connection
        • Install Updates for Panorama When Not Internet-Connected
        • Install Updates Automatically for Panorama without an Internet Connection
        • Migrate Panorama Logs to the New Log Format
      • Transition to a Different Panorama Model
        • Migrate from a Panorama Virtual Appliance to an M-Series Appliance
        • Migrate a Panorama Virtual Appliance to a Different Hypervisor
        • Migrate from an M-Series Appliance to a Panorama Virtual Appliance
        • Migrate from an M-100 Appliance to an M-500 Appliance
        • Migrate from an M-100 or M-500 Appliance to an M-200 or M-600 Appliance
      • Access and Navigate Panorama Management Interfaces
        • Log in to the Panorama Web Interface
        • Navigate the Panorama Web Interface
        • Log in to the Panorama CLI
      • Set Up Administrative Access to Panorama
        • Configure an Admin Role Profile
        • Configure an Access Domain
        • Configure Administrative Accounts and Authentication
          • Configure a Panorama Administrator Account
          • Configure Local or External Authentication for Panorama Administrators
          • Configure a Panorama Administrator with Certificate-Based Authentication for the Web Interface
          • Configure an Administrator with SSH Key-Based Authentication for the CLI
          • Configure RADIUS Authentication for Panorama Administrators
          • Configure TACACS+ Authentication for Panorama Administrators
          • Configure SAML Authentication for Panorama Administrators
      • Set Up Authentication Using Custom Certificates
        • How Are SSL/TLS Connections Mutually Authenticated?
        • Configure Authentication Using Custom Certificates on Panorama
        • Configure Authentication Using Custom Certificates on Managed Devices
        • Add New Client Devices
        • Change Certificates
          • Change a Server Certificate
          • Change a Client Certificate
          • Change a Root or Intermediate CA Certificate
    • Manage Firewalls
      • Add a Firewall as a Managed Device
      • Install the Device Certificate for Managed Firewalls
        • Install the Device Certificate for a Managed Firewall
        • Install the Device Certificate for Multiple Managed Firewalls
      • Set Up Zero Touch Provisioning
        • ZTP Overview
          • About ZTP
          • ZTP Configuration Elements
        • Install the ZTP Plugin
          • Install the ZTP Plugin on Panorama
          • Register Panorama with the ZTP Service
            • Register Panorama with the ZTP Service for New Deployments
            • Register Panorama with the ZTP Service for Existing Deployments
        • Configure the ZTP Installer Administrator Account
        • Add ZTP Firewalls to Panorama
          • Add a ZTP Firewall to Panorama
          • Import Multiple ZTP Firewalls to Panorama
        • Use the CLI for ZTP Tasks
        • Uninstall the ZTP Plugin
      • Manage Device Groups
        • Add a Device Group
        • Create a Device Group Hierarchy
        • Create Objects for Use in Shared or Device Group Policy
        • Revert to Inherited Object Values
        • Manage Unused Shared Objects
        • Manage Precedence of Inherited Objects
        • Move or Clone a Policy Rule or Object to a Different Device Group
        • Push a Policy Rule to a Subset of Firewalls
        • Manage the Rule Hierarchy
      • Manage Templates and Template Stacks
        • Template Capabilities and Exceptions
        • Add a Template
        • Configure a Template Stack
        • Configure a Template or Template Stack Variable
        • Import and Overwrite Existing Template Stack Variables
        • Override a Template or Template Stack Value
          • Override a Template Value on the Firewall
          • Override a Template Value Using a Template Stack
          • Override a Template or Template Stack Value Using Variables
        • Disable/Remove Template Settings
      • Manage the Master Key from Panorama
      • Redistribute Data to Managed Firewalls
      • Transition a Firewall to Panorama Management
        • Plan the Transition to Panorama Management
        • Migrate a Firewall to Panorama Management
        • Migrate a Firewall HA Pair to Panorama Management
        • Load a Partial Firewall Configuration into Panorama
        • Localize a Panorama Pushed Configuration on a Managed Firewall
      • Device Monitoring on Panorama
        • Monitor Device Health
        • Monitor Policy Rule Usage
      • Use Case: Configure Firewalls Using Panorama
        • Device Groups in this Use Case
        • Templates in this Use Case
        • Set Up Your Centralized Configuration and Policies
          • Add the Managed Firewalls and Deploy Updates
          • Use Templates to Administer a Base Configuration
          • Use Device Groups to Push Policy Rules
          • Preview the Rules and Commit Changes
    • Manage Log Collection
      • Configure a Managed Collector
      • Configure Authentication for a Dedicated Log Collector
        • Configure an Administrative Account for a Dedicated Log Collector
        • Configure RADIUS Authentication for a Dedicated Log Collector
        • Configure TACACS+ Authentication for a Dedicated Log Collector
        • Configure LDAP Authentication for a Dedicated Log Collector
      • Manage Collector Groups
        • Configure a Collector Group
        • Configure Authentication with Custom Certificates Between Log Collectors
        • Move a Log Collector to a Different Collector Group
        • Remove a Firewall from a Collector Group
      • Configure Log Forwarding to Panorama
      • Configure Syslog Forwarding to External Destinations
      • Forward Logs to Cortex Data Lake
      • Verify Log Forwarding to Panorama
      • Modify Log Forwarding and Buffering Defaults
      • Configure Log Forwarding from Panorama to External Destinations
      • Log Collection Deployments
        • Deploy Panorama with Dedicated Log Collectors
        • Deploy Panorama M-Series Appliances with Local Log Collectors
        • Deploy Panorama Virtual Appliances with Local Log Collectors
        • Deploy Panorama Virtual Appliances in Legacy Mode with Local Log Collection
    • Manage WildFire Appliances
      • Add Standalone WildFire Appliances to Manage with Panorama
      • Configure Basic WildFire Appliance Settings on Panorama
        • Configure Authentication for a WildFire Appliance
          • Configure An Administrative Account for a WildFire Appliance
          • Configure RADIUS Authentication for a WildFire Appliance
          • Configure TACACS+ Authentication for a WildFire Appliance
          • Configure LDAP Authentication for a WildFire Appliance
      • Set Up Authentication Using Custom Certificates on WildFire Appliances and Clusters
        • Configure a Custom Certificate for a Panorama Managed WildFire Appliance
        • Configure Authentication with a Single Custom Certificate for a WildFire Cluster
        • Apply Custom Certificates on a WildFire Appliance Configured through Panorama
      • Remove a WildFire Appliance from Panorama Management
      • Manage WildFire Clusters
        • Configure a Cluster Centrally on Panorama
          • Configure a Cluster and Add Nodes on Panorama
          • Configure General Cluster Settings on Panorama
          • Configure Authentication for a WildFire Cluster
            • Configure an Administrative Account for a WildFire Cluster
            • Configure RADIUS Authentication for a WildFire Cluster
            • Configure TACACS+ Authentication for a WildFire Cluster
            • Configure LDAP Authentication for a WildFire Cluster
          • Remove a Cluster from Panorama Management
          • Configure Appliance-to-Appliance Encryption Using Predefined Certificates Centrally on Panorama
          • Configure Appliance-to-Appliance Encryption Using Custom Certificates Centrally on Panorama
        • View WildFire Cluster Status Using Panorama
        • Upgrade a Cluster Centrally on Panorama with an Internet Connection
        • Upgrade a Cluster Centrally on Panorama without an Internet Connection
    • Manage Licenses and Updates
      • Manage Licenses on Firewalls Using Panorama
      • Deploy Upgrades to Firewalls, Log Collectors, and WildFire Appliances Using Panorama
        • Supported Updates
        • Schedule a Content Update Using Panorama
        • Upgrade Log Collectors When Panorama Is Internet-Connected
        • Upgrade Log Collectors When Panorama Is Not Internet-Connected
        • Upgrade Firewalls When Panorama Is Internet-Connected
        • Upgrade Firewalls When Panorama Is Not Internet-Connected
        • Upgrade a ZTP Firewall
        • Revert Content Updates from Panorama
    • Monitor Network Activity
      • Use Panorama for Visibility
        • Monitor the Network with the ACC and AppScope
        • Analyze Log Data
        • Generate, Schedule, and Email Reports
        • Configure Key Limits for Scheduled Reports
      • Ingest Traps ESM Logs on Panorama
      • Use Case: Monitor Applications Using Panorama
      • Use Case: Respond to an Incident Using Panorama
        • Incident Notification
        • Review the Widgets in the ACC
        • Review Threat Logs
        • Review WildFire Logs
        • Review Data Filtering Logs
        • Update Security Rules
    • Panorama High Availability
      • Panorama HA Prerequisites
      • Priority and Failover on Panorama in HA
      • Failover Triggers
        • HA Heartbeat Polling and Hello Messages
        • HA Path Monitoring
      • Logging Considerations in Panorama HA
        • Logging Failover on a Panorama Virtual Appliance in Legacy Mode
        • Logging Failover on an M-Series Appliance or Panorama Virtual Appliance in Panorama Mode
      • Synchronization Between Panorama HA Peers
      • Manage a Panorama HA Pair
        • Set Up HA on Panorama
        • Set Up Authentication Using Custom Certificates Between HA Peers
        • Test Panorama HA Failover
        • Switch Priority after Panorama Failover to Resume NFS Logging
        • Restore the Primary Panorama to the Active State
    • Administer Panorama
      • Preview, Validate, or Commit Configuration Changes
      • Enable Automated Commit Recovery
      • Manage Panorama and Firewall Configuration Backups
        • Schedule Export of Configuration Files
        • Save and Export Panorama and Firewall Configurations
        • Revert Panorama Configuration Changes
        • Configure the Maximum Number of Configuration Backups on Panorama
        • Load a Configuration Backup on a Managed Firewall
      • Compare Changes in Panorama Configurations
      • Manage Locks for Restricting Configuration Changes
      • Add Custom Logos to Panorama
      • Use the Panorama Task Manager
      • Manage Storage Quotas and Expiration Periods for Logs and Reports
        • Log and Report Storage
        • Log and Report Expiration Periods
        • Configure Storage Quotas and Expiration Periods for Logs and Reports
        • Configure the Run Time for Panorama Reports
      • Monitor Panorama
        • Panorama System and Configuration Logs
        • Monitor Panorama and Log Collector Statistics Using SNMP
      • Reboot or Shut Down Panorama
      • Configure Panorama Password Profiles and Complexity
    • Panorama Plugins
      • About Panorama Plugins
        • Install Panorama Plugins
      • VM-Series Plugin and Panorama Plugins
        • Install the VM-Series Plugin on Panorama
    • Troubleshooting
      • Troubleshoot Panorama System Issues
        • Generate Diagnostic Files for Panorama
        • Diagnose Panorama Suspended State
        • Monitor the File System Integrity Check
        • Manage Panorama Storage for Software and Content Updates
        • Recover from Split Brain in Panorama HA Deployments
      • Troubleshoot Log Storage and Connection Issues
        • Verify Panorama Port Usage
        • Resolve Zero Log Storage for a Collector Group
        • Replace a Failed Disk on an M-Series Appliance
        • Replace the Virtual Disk on an ESXi Server
        • Replace the Virtual Disk on vCloud Air
        • Migrate Logs to a New M-Series Appliance in Log Collector Mode
        • Migrate Logs to a New M-Series Appliance in Panorama Mode
        • Migrate Logs to a New M-Series Appliance Model in Panorama Mode in High Availability
        • Migrate Logs to the Same M-Series Appliance Model in Panorama Mode in High Availability
        • Migrate Log Collectors after Failure/RMA of Non-HA Panorama
        • Regenerate Metadata for M-Series Appliance RAID Pairs
        • View Log Query Jobs
      • Replace an RMA Firewall
        • Partial Device State Generation for Firewalls
        • Before Starting RMA Firewall Replacement
        • Restore the Firewall Configuration after Replacement
      • Troubleshoot Commit Failures
      • Troubleshoot Registration or Serial Number Errors
      • Troubleshoot Reporting Errors
      • Troubleshoot Device Management License Errors
      • Troubleshoot Automatically Reverted Firewall Configurations
      • Complete Content Update When Panorama HA Peer is Down
      • View Task Success or Failure Status
      • Test Policy Match and Connectivity for Managed Devices
        • Troubleshoot Policy Rule Traffic Match
        • Troubleshoot Connectivity to Network Resources
      • Downgrade from Panorama 10.0

    Document:Panorama Administrator's Guide


    Verify Log Forwarding to Panorama

    Download PDF
    Last Updated:
    Jul 23, 2022
    Current Version:
    10.0 (EoL)
    • Version 11.0
    • Version 10.2
    • Version 10.1
    • Version 10.0 (EoL)
    • Version 9.1

    Table of Contents


    Filter icon
    Filter
    Panorama Overview
    About Panorama
    Panorama Models
    Centralized Firewall Configuration and Update Management
    Context Switch—Firewall or Panorama
    Total Configuration Size for Panorama
    Templates and Template Stacks
    Device Groups
    Device Group Hierarchy
    Device Group Policies
    Device Group Objects
    Centralized Logging and Reporting
    Managed Collectors and Collector Groups
    Local and Distributed Log Collection
    Caveats for a Collector Group with Multiple Log Collectors
    Log Forwarding Options
    Centralized Reporting
    Data Redistribution Using Panorama
    Role-Based Access Control
    Administrative Roles
    Authentication Profiles and Sequences
    Access Domains
    Administrative Authentication
    Panorama Commit, Validation, and Preview Operations
    Plan Your Panorama Deployment
    Deploy Panorama: Task Overview
    Set Up Panorama
    Determine Panorama Log Storage Requirements
    Manage Large-Scale Firewall Deployments
    Determine the Optimal Large-Scale Firewall Deployment Solution
    Increased Device Management Capacity for M-600 and Panorama Virtual Appliance
    Increased Device Management Capacity Requirements
    Deploy Panorama for Increased Device Management
    Install Panorama for Increased Device Management Capacity
    Upgrade Panorama for Increased Device Management Capacity
    Set Up the Panorama Virtual Appliance
    Setup Prerequisites for the Panorama Virtual Appliance
    Install the Panorama Virtual Appliance
    Install Panorama on VMware
    Install Panorama on an ESXi Server
    Install Panorama on vCloud Air
    Support for VMware Tools on the Panorama Virtual Appliance
    Set Up Panorama on Alibaba Cloud
    Upload the Panorama Virtual Appliance Image to Alibaba Cloud
    Install Panorama on Alibaba Cloud
    Install Panorama on AWS
    Install Panorama on AWS GovCloud
    Install Panorama on Azure
    Install Panorama on Google Cloud Platform
    Install Panorama on Hyper-V
    Install Panorama on KVM
    Set Up Panorama on Oracle Cloud Infrastructure (OCI)
    Upload the Panorama Virtual Appliance Image to OCI
    Install Panorama on Oracle Cloud Infrastructure (OCI)
    Generate a SSH Key for Panorama on OCI
    Perform Initial Configuration of the Panorama Virtual Appliance
    Set Up The Panorama Virtual Appliance as a Log Collector
    Set Up the Panorama Virtual Appliance with Local Log Collector
    Set up a Panorama Virtual Appliance in Panorama Mode
    Set up a Panorama Virtual Appliance in Management Only Mode
    Expand Log Storage Capacity on the Panorama Virtual Appliance
    Preserve Existing Logs When Adding Storage on Panorama Virtual Appliance in Legacy Mode
    Add a Virtual Disk to Panorama on an ESXi Server
    Add a Virtual Disk to Panorama on vCloud Air
    Add a Virtual Disk to Panorama on Alibaba Cloud
    Add a Virtual Disk to Panorama on AWS
    Add a Virtual Disk to Panorama on Azure
    Add a Virtual Disk to Panorama on Google Cloud Platform
    Add a Virtual Disk to Panorama on Hyper-V
    Add a Virtual Disk to Panorama on KVM
    Add a Virtual Disk to Panorama on Oracle Cloud Infrastructure (OCI)
    Mount the Panorama ESXi Server to an NFS Datastore
    Increase CPUs and Memory on the Panorama Virtual Appliance
    Increase CPUs and Memory for Panorama on an ESXi Server
    Increase CPUs and Memory for Panorama on vCloud Air
    Increase CPUs and Memory for Panorama on Alibaba Cloud
    Increase CPUs and Memory for Panorama on AWS
    Increase CPUs and Memory for Panorama on Azure
    Increase CPUs and Memory for Panorama on Google Cloud Platform