Verify Log Forwarding to Panorama

After you Configure Log Forwarding to Panorama or to the Logging Service test that your configuration succeeded.
  1. Access the firewall CLI.
  2. If you configured Log Collectors, verify that each firewall has a log forwarding preference list.
    > show log-collector preference-list
    If the Collector Group has only one Log Collector, the output will look something like this:
    Forward to all: No 
    Log collector Preference List 
    Serial Number: 003001000024 
    IP Address: 10.2.133.48 
    IPV6 Address: unknown 
  3. Verify that each firewall is forwarding logs.
    > show logging-status
    For successful forwarding, the output indicates that the log forwarding agent is active.
    • For a Panorama virtual appliance, the agent is Panorama.
    • For an M-500 appliance or M-100 appliance, the agent is a Log Collector.
    • For the Logging Service, the agent is Log Collection Service.. And the
      ‘Log Collection log forwarding agent’ is active and connected to <IP_address>.
  4. View the average logging rate. The displayed rate will be the average logs/second for the last five minutes.
    • If Log Collectors receive the logs, access the Panorama web interface, select PanoramaManaged Collectors and click the Statistics link in the far-right column.
    • If a Panorama virtual appliance in Legacy mode receives the logs, access the Panorama CLI and run the following command: debug log-collector log-collection-stats show incoming-logs
    This command also works on an M-Series appliance.

Related Documentation