Verify Log Forwarding to Panorama
- Access the firewall CLI.
- If you configured Log Collectors, verify that each firewall
has a log forwarding preference list.
> show log-collector preference-listIf the Collector Group has only one Log Collector, the output will look something like this:
Forward to all: No Log collector Preference List Serial Number: 003001000024 IP Address: 10.2.133.48 IPV6 Address: unknown
- Verify that each firewall is forwarding logs.
> show logging-statusFor successful forwarding, the output indicates that the log forwarding agent is active.
- For a Panorama virtual appliance, the agent is Panorama.
- For an M-500 appliance or M-100 appliance, the agent is a Log Collector.
- For the Logging Service, the agent is Log Collection Service.. And the
‘Log Collection log forwarding agent’ is active and connected to <IP_address>.
- View the average logging rate. The displayed rate will
be the average logs/second for the last five minutes.
This command also works on an M-Series appliance.
- If Log Collectors receive the logs, access the Panorama web interface, select PanoramaManaged Collectors and click the Statistics link in the far-right column.
- If a Panorama virtual appliance in Legacy mode receives the logs, access the Panorama CLI and run the following command: debug log-collector log-collection-stats show incoming-logs
Manage Log Collection
Manage Log Collection All Palo Alto Networks firewalls can generate logs that provide an audit trail of firewall activities. For Centralized Logging and Reporting , ...
Migrate Logs to a New M-Series Appliance Model in Panorama Mode in High Availability
Procedure to migrate logs from a decommissioned M-Series appliance in a HA pair to a new M-Series appliance of a different model. ...
Determine Panorama Log Storage Requirements
Determine Panorama Log Storage Requirements When you Plan Your Panorama Deployment , estimate how much log storage capacity Panorama requires to determine which Panorama Models ...
Migrate Logs to a New M-Series Appliance in Panorama Mode
Procedure to migrate logs from a decommissioned M-Series appliance, that is not in a HA pair, to a new M-Series appliance. ...
Migrate Logs to the Same M-Series Appliance Model in Panorama Mode in High Availability
Procedure to migrate logs from a decommissioned M-Series appliance in a HA pair to a new M-Series appliance of the same model. ...
Migrate Logs to a New M-Series Appliance in Log Collector M...
Migrate Logs to a New M-Series Appliance in Log Collector Mode If you need to replace an M-500 or M-100 appliance in Log Collector mode ...
Deploy Panorama with Dedicated Log Collectors
Deploy Panorama with Dedicated Log Collectors The following figures illustrate Panorama in a distributed log collection deployment. In these examples, the Panorama management server comprises ...
Managed Collectors and Collector Groups
Managed Collectors and Collector Groups Panorama uses Log Collectors to aggregate logs from managed firewalls. When generating reports, Panorama queries the Log Collectors for log ...
PA-7000 Series Firewall Log Forwarding to Panorama
PA-7000 Series Firewall Log Forwarding to Panorama You can now forward logs from PA-7000 Series firewalls to Panorama for improved log retention, which helps you ...