<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Best Practices with Log Collection Design in Panorama in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/best-practices-with-log-collection-design-in-panorama/ta-p/1228363</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-05-07 at 3.13.56 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67457i898FDA9321648EA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-05-07 at 3.13.56 PM.png" alt="Screenshot 2025-05-07 at 3.13.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Logging is a critical component in network security, helping organizations maintain visibility, compliance, and forensics. Panorama, with its powerful log collection and analysis capabilities, supports distributed environments at scale. However, optimal performance depends on careful planning and adherence to best practices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This article provides practical guidance across &lt;/SPAN&gt;&lt;STRONG&gt;system requirements&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;architecture&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;configuration&lt;/STRONG&gt;&lt;SPAN&gt;, and &lt;/SPAN&gt;&lt;STRONG&gt;migration&lt;/STRONG&gt;&lt;SPAN&gt; strategies to design a robust and efficient Panorama logging infrastructure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;System Requirements&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;CPU &amp;amp; Memory&lt;/STRONG&gt;&lt;SPAN&gt;: A minimum of &lt;/SPAN&gt;&lt;STRONG&gt;16 vCPUs&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;64GB RAM&lt;/STRONG&gt;&lt;SPAN&gt; is recommended for Panorama in &lt;/SPAN&gt;&lt;STRONG&gt;Log Collector&lt;/STRONG&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;Logger&lt;/STRONG&gt;&lt;SPAN&gt; mode in high logging rate environments.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Disk Type (Virtual Appliances)&lt;/STRONG&gt;&lt;SPAN&gt;: Choose a disk type with &lt;/SPAN&gt;&lt;STRONG&gt;high IOPS&lt;/STRONG&gt;&lt;SPAN&gt; to improve &lt;/SPAN&gt;&lt;STRONG&gt;Logs Per Second (LPS)&lt;/STRONG&gt;&lt;SPAN&gt; performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Multiple Disks&lt;/STRONG&gt;&lt;SPAN&gt;: Use &lt;/SPAN&gt;&lt;STRONG&gt;more than one disk&lt;/STRONG&gt;&lt;SPAN&gt; in the Log Collector appliance to distribute IOPS load effectively.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Version Consistency&lt;/STRONG&gt;&lt;SPAN&gt;: All Log Collectors in a &lt;/SPAN&gt;&lt;STRONG&gt;Collector Group&lt;/STRONG&gt;&lt;SPAN&gt; must run &lt;/SPAN&gt;&lt;STRONG&gt;the same PAN-OS version&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Uniform Disk Configuration&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Use the same&lt;/SPAN&gt;&lt;STRONG&gt; number of disks&lt;/STRONG&gt;&lt;SPAN&gt; across Log Collectors in a Collector Group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;For virtual appliances, ensure &lt;/SPAN&gt;&lt;STRONG&gt;identical system profiles&lt;/STRONG&gt;&lt;SPAN&gt; (CPU, memory, disk type, number of disks) across all Log Collectors.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Architecture&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Collector Group Quorum&lt;/STRONG&gt;&lt;SPAN&gt;: Deploy a &lt;/SPAN&gt;&lt;STRONG&gt;minimum of three Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; in a group to satisfy quorum requirements and ensure Logging Resiliency.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Multiple Collector Groups&lt;/STRONG&gt;&lt;SPAN&gt;: In high LPS environments, &lt;/SPAN&gt;&lt;STRONG&gt;distribute logs&lt;/STRONG&gt;&lt;SPAN&gt; across &lt;/SPAN&gt;&lt;STRONG&gt;multiple Collector Groups&lt;/STRONG&gt;&lt;SPAN&gt; for better performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Latency Considerations&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;STRONG&gt;&amp;lt;10ms&lt;/STRONG&gt;&lt;SPAN&gt; between Log Collectors in a group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;STRONG&gt;&amp;lt;500ms&lt;/STRONG&gt;&lt;SPAN&gt; between firewalls and their Log Collectors.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Capacity Planning&lt;/STRONG&gt;&lt;SPAN&gt;: Always &lt;/SPAN&gt;&lt;STRONG&gt;add 15% overhead&lt;/STRONG&gt;&lt;SPAN&gt; to both log ingestion and storage calculations.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Example: For 15,000 logs/sec, provision for &lt;/SPAN&gt;&lt;STRONG&gt;17,250 logs/sec&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Dedicated vs Local Collectors&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;STRONG&gt;Prefer Dedicated Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; over local ones for better performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Local collectors share resources with management and may have reduced performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Appliance Selection&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;In high logging environments, &lt;/SPAN&gt;&lt;STRONG&gt;M-Series appliances&lt;/STRONG&gt;&lt;SPAN&gt; offer better performance than virtual appliances.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;In &lt;/SPAN&gt;&lt;STRONG&gt;Hybrid Cloud&lt;/STRONG&gt;&lt;SPAN&gt; deployments, place &lt;/SPAN&gt;&lt;STRONG&gt;Dedicated Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; in the &lt;/SPAN&gt;&lt;STRONG&gt;same cloud region&lt;/STRONG&gt;&lt;SPAN&gt; to reduce egress charges.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;For &lt;/SPAN&gt;&lt;STRONG&gt;globally distributed networks&lt;/STRONG&gt;&lt;SPAN&gt;, centralize management but &lt;/SPAN&gt;&lt;STRONG&gt;deploy regional Dedicated Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log Forwarding Preference List&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Configure a &lt;/SPAN&gt;&lt;STRONG&gt;preference list&lt;/STRONG&gt;&lt;SPAN&gt; on firewalls for log forwarding.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Include &lt;/SPAN&gt;&lt;STRONG&gt;at least two Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; to ensure redundancy.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Enable “&lt;/SPAN&gt;&lt;STRONG&gt;Forward to all collectors in the preference list&lt;/STRONG&gt;&lt;SPAN&gt;” to distribute logs evenly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Interface Separation&lt;/STRONG&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Use &lt;/SPAN&gt;&lt;STRONG&gt;separate interfaces&lt;/STRONG&gt;&lt;SPAN&gt; for:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Log Collection&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Inter-LC communication&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Management traffic&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Prevents log queues from interfering with keepalive packets.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Efficient Logging Configuration&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Log &lt;/SPAN&gt;&lt;STRONG&gt;at session end&lt;/STRONG&gt;&lt;SPAN&gt; in security policies for efficient storage.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log-Collector Management&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Avoid removing a Log Collector from a group unless necessary.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Removing wipes all logs on that collector.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Re-adding it requires data rebalancing, which can be time-consuming.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Migration&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;Phased Migration Strategy:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Cross-Model Log Migration is not supported today.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Keep the &lt;/SPAN&gt;&lt;STRONG&gt;old Collector Group&lt;/STRONG&gt;&lt;SPAN&gt; active while &lt;/SPAN&gt;&lt;STRONG&gt;redirecting firewalls&lt;/STRONG&gt;&lt;SPAN&gt; to the new group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;After the &lt;/SPAN&gt;&lt;STRONG&gt;log retention period&lt;/STRONG&gt;&lt;SPAN&gt; ends for the old data, &lt;/SPAN&gt;&lt;STRONG&gt;decommission&lt;/STRONG&gt;&lt;SPAN&gt; the old group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Conclusion&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;SPAN&gt;Proper&lt;/SPAN&gt;&lt;SPAN&gt; planning and adherence to best practices in Panorama log collection can drastically improve the visibility, reliability, and scalability of your logging infrastructure. Whether you're managing a few firewalls or a globally distributed network, these best practices help ensure performance and operational efficiency without compromising on data retention or log accessibility.&lt;/SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 07 May 2025 09:54:46 GMT</pubDate>
    <dc:creator>shv</dc:creator>
    <dc:date>2025-05-07T09:54:46Z</dc:date>
    <item>
      <title>Best Practices with Log Collection Design in Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/best-practices-with-log-collection-design-in-panorama/ta-p/1228363</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-05-07 at 3.13.56 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67457i898FDA9321648EA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-05-07 at 3.13.56 PM.png" alt="Screenshot 2025-05-07 at 3.13.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Logging is a critical component in network security, helping organizations maintain visibility, compliance, and forensics. Panorama, with its powerful log collection and analysis capabilities, supports distributed environments at scale. However, optimal performance depends on careful planning and adherence to best practices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This article provides practical guidance across &lt;/SPAN&gt;&lt;STRONG&gt;system requirements&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;architecture&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;configuration&lt;/STRONG&gt;&lt;SPAN&gt;, and &lt;/SPAN&gt;&lt;STRONG&gt;migration&lt;/STRONG&gt;&lt;SPAN&gt; strategies to design a robust and efficient Panorama logging infrastructure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;System Requirements&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;CPU &amp;amp; Memory&lt;/STRONG&gt;&lt;SPAN&gt;: A minimum of &lt;/SPAN&gt;&lt;STRONG&gt;16 vCPUs&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;64GB RAM&lt;/STRONG&gt;&lt;SPAN&gt; is recommended for Panorama in &lt;/SPAN&gt;&lt;STRONG&gt;Log Collector&lt;/STRONG&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;Logger&lt;/STRONG&gt;&lt;SPAN&gt; mode in high logging rate environments.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Disk Type (Virtual Appliances)&lt;/STRONG&gt;&lt;SPAN&gt;: Choose a disk type with &lt;/SPAN&gt;&lt;STRONG&gt;high IOPS&lt;/STRONG&gt;&lt;SPAN&gt; to improve &lt;/SPAN&gt;&lt;STRONG&gt;Logs Per Second (LPS)&lt;/STRONG&gt;&lt;SPAN&gt; performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Multiple Disks&lt;/STRONG&gt;&lt;SPAN&gt;: Use &lt;/SPAN&gt;&lt;STRONG&gt;more than one disk&lt;/STRONG&gt;&lt;SPAN&gt; in the Log Collector appliance to distribute IOPS load effectively.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Version Consistency&lt;/STRONG&gt;&lt;SPAN&gt;: All Log Collectors in a &lt;/SPAN&gt;&lt;STRONG&gt;Collector Group&lt;/STRONG&gt;&lt;SPAN&gt; must run &lt;/SPAN&gt;&lt;STRONG&gt;the same PAN-OS version&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Uniform Disk Configuration&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Use the same&lt;/SPAN&gt;&lt;STRONG&gt; number of disks&lt;/STRONG&gt;&lt;SPAN&gt; across Log Collectors in a Collector Group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;For virtual appliances, ensure &lt;/SPAN&gt;&lt;STRONG&gt;identical system profiles&lt;/STRONG&gt;&lt;SPAN&gt; (CPU, memory, disk type, number of disks) across all Log Collectors.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Architecture&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Collector Group Quorum&lt;/STRONG&gt;&lt;SPAN&gt;: Deploy a &lt;/SPAN&gt;&lt;STRONG&gt;minimum of three Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; in a group to satisfy quorum requirements and ensure Logging Resiliency.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Multiple Collector Groups&lt;/STRONG&gt;&lt;SPAN&gt;: In high LPS environments, &lt;/SPAN&gt;&lt;STRONG&gt;distribute logs&lt;/STRONG&gt;&lt;SPAN&gt; across &lt;/SPAN&gt;&lt;STRONG&gt;multiple Collector Groups&lt;/STRONG&gt;&lt;SPAN&gt; for better performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Latency Considerations&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;STRONG&gt;&amp;lt;10ms&lt;/STRONG&gt;&lt;SPAN&gt; between Log Collectors in a group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;STRONG&gt;&amp;lt;500ms&lt;/STRONG&gt;&lt;SPAN&gt; between firewalls and their Log Collectors.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Capacity Planning&lt;/STRONG&gt;&lt;SPAN&gt;: Always &lt;/SPAN&gt;&lt;STRONG&gt;add 15% overhead&lt;/STRONG&gt;&lt;SPAN&gt; to both log ingestion and storage calculations.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Example: For 15,000 logs/sec, provision for &lt;/SPAN&gt;&lt;STRONG&gt;17,250 logs/sec&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Dedicated vs Local Collectors&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;STRONG&gt;Prefer Dedicated Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; over local ones for better performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Local collectors share resources with management and may have reduced performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Appliance Selection&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;In high logging environments, &lt;/SPAN&gt;&lt;STRONG&gt;M-Series appliances&lt;/STRONG&gt;&lt;SPAN&gt; offer better performance than virtual appliances.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;In &lt;/SPAN&gt;&lt;STRONG&gt;Hybrid Cloud&lt;/STRONG&gt;&lt;SPAN&gt; deployments, place &lt;/SPAN&gt;&lt;STRONG&gt;Dedicated Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; in the &lt;/SPAN&gt;&lt;STRONG&gt;same cloud region&lt;/STRONG&gt;&lt;SPAN&gt; to reduce egress charges.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;For &lt;/SPAN&gt;&lt;STRONG&gt;globally distributed networks&lt;/STRONG&gt;&lt;SPAN&gt;, centralize management but &lt;/SPAN&gt;&lt;STRONG&gt;deploy regional Dedicated Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log Forwarding Preference List&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Configure a &lt;/SPAN&gt;&lt;STRONG&gt;preference list&lt;/STRONG&gt;&lt;SPAN&gt; on firewalls for log forwarding.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Include &lt;/SPAN&gt;&lt;STRONG&gt;at least two Log Collectors&lt;/STRONG&gt;&lt;SPAN&gt; to ensure redundancy.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Enable “&lt;/SPAN&gt;&lt;STRONG&gt;Forward to all collectors in the preference list&lt;/STRONG&gt;&lt;SPAN&gt;” to distribute logs evenly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Interface Separation&lt;/STRONG&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Use &lt;/SPAN&gt;&lt;STRONG&gt;separate interfaces&lt;/STRONG&gt;&lt;SPAN&gt; for:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Log Collection&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Inter-LC communication&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Management traffic&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Prevents log queues from interfering with keepalive packets.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Efficient Logging Configuration&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Log &lt;/SPAN&gt;&lt;STRONG&gt;at session end&lt;/STRONG&gt;&lt;SPAN&gt; in security policies for efficient storage.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log-Collector Management&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Avoid removing a Log Collector from a group unless necessary.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Removing wipes all logs on that collector.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Re-adding it requires data rebalancing, which can be time-consuming.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Migration&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;Phased Migration Strategy:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Cross-Model Log Migration is not supported today.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Keep the &lt;/SPAN&gt;&lt;STRONG&gt;old Collector Group&lt;/STRONG&gt;&lt;SPAN&gt; active while &lt;/SPAN&gt;&lt;STRONG&gt;redirecting firewalls&lt;/STRONG&gt;&lt;SPAN&gt; to the new group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;After the &lt;/SPAN&gt;&lt;STRONG&gt;log retention period&lt;/STRONG&gt;&lt;SPAN&gt; ends for the old data, &lt;/SPAN&gt;&lt;STRONG&gt;decommission&lt;/STRONG&gt;&lt;SPAN&gt; the old group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;Conclusion&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;SPAN&gt;Proper&lt;/SPAN&gt;&lt;SPAN&gt; planning and adherence to best practices in Panorama log collection can drastically improve the visibility, reliability, and scalability of your logging infrastructure. Whether you're managing a few firewalls or a globally distributed network, these best practices help ensure performance and operational efficiency without compromising on data retention or log accessibility.&lt;/SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 May 2025 09:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/best-practices-with-log-collection-design-in-panorama/ta-p/1228363</guid>
      <dc:creator>shv</dc:creator>
      <dc:date>2025-05-07T09:54:46Z</dc:date>
    </item>
  </channel>
</rss>

