<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Understanding Panorama System Mode Transitions in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/understanding-panorama-system-mode-transitions/ta-p/1230681</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-06-02 at 3.28.33 PM (2).png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67832iF854CD45D031E9B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-06-02 at 3.28.33 PM (2).png" alt="Screenshot 2025-06-02 at 3.28.33 PM (2).png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This document outlines the various system modes available for Palo Alto Networks &lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;and provides guidance on transitioning between them. &lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;offers flexibility with its different modes: Panorama, Management-Only, and Logger.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reasons for changing system modes might include optimizing resource allocation by separating log collection and management, transitioning to dedicated logging with Logger mode, or simplifying operations to management-only. Each mode serves a specific purpose and knowing the prerequisites and considerations for each transition is essential to avoid data loss and ensure smooth operations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;1. Changing from Panorama Mode to Management-Only Mode&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This section details the process and considerations for moving a Panorama appliance from its default Panorama mode (managing devices and processing their logs) to Management-Only mode (solely for device management).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Summary of Mode Change: Panorama &amp;gt; Management-Only&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;No loss of configuration.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Firewall Logs are lost (as &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;management-only&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; mode disables the Log Collector processes).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;There is no officially supported method to retain these logs; attempting to manipulate disks is not supported.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log Collector Group Assignment:&lt;/STRONG&gt;&lt;SPAN&gt; All managed firewalls &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;must&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; be assigned to a Log Collector Group. Refer to Palo Alto Networks Knowledge Base article&lt;/SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008Ub7CAE" target="_blank" rel="noopener"&gt; &lt;SPAN&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008Ub7CAE&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;If there are no Log Collector Groups and no Dedicated Log Collectors available, create a “dummy” Log Collector Group and a Dedicated Log Collector and assign managed devices to this temporary Group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Please note that adding a disconnected Dedicated Log Collector to a Log Collector Group must be done via CLI as it is not possible via GUI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;set log-collector-group {DUMMY_LCG_NAME} logfwd-setting collectors {DUMMY_DLC_SERIAL_NUMBER}&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Example: &lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;set log-collector-group EMPTY_LCG logfwd-setting collectors 1234&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;If there are any disconnected managed devices not assigned to a Log Collector Group, these need to be removed, or assigned to an LCG via CLI as it is not possible to assign a disconnected device to an LCG via GUI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;set log-collector-group {DUMMY_LCG_NAME} logfwd-setting devices {DEVICE_SERIAL_NUMBER}&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Example:&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt; set log-collector-group BLANK_LCG logfwd-setting devices 4567&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Isolation of Local Log Collectors (LLCs):&lt;/STRONG&gt;&lt;SPAN&gt; Ensure that any Local Log Collectors (running on the Panorama itself) are &lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt; part of any Log Collector Groups. This might require removing the Local Log Collectors from existing Log Collector Groups.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Considerations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Loss of Local Logs:&lt;/STRONG&gt;&lt;SPAN&gt; Switching to Management-Only mode will stop local log collection on Panorama. Ensure you have dedicated Log Collectors in place to handle logging for your managed devices.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;HA Pair Transition:&lt;/STRONG&gt;&lt;SPAN&gt; When dealing with an HA pair, it's recommended to start with the secondary (passive) Panorama. Be aware of potential temporary failovers due to operational mode mismatches.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Potential Communication Issues:&lt;/STRONG&gt;&lt;SPAN&gt; After the mode change, you might encounter temporary communication issues with existing Dedicated Log Collectors (e.g., "ring version mismatch"), which may require a "commit force" on Panorama to resolve.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;2. Changing from Management-Only Mode to Panorama Mode&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This section outlines the considerations for enabling local log collection capabilities on a Panorama that is currently in Management-Only mode.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Summary of Mode Change: Management-Only &amp;gt; Panorama&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;No loss of configuration.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;There are no logs to lose (as &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;management-only&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; mode doesn't collect logs).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;In the case of Virtual Panorama appliances, at least one logging disk of 2TB needs to be attached to the VM before the switch.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Considerations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Enabling Local Logging:&lt;/STRONG&gt;&lt;SPAN&gt; This change will allow the Panorama to act as a Local Log Collector. You will need to configure Log Collector Groups to include the local log collector if you wish for the Panorama to store logs.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Resource Usage:&lt;/STRONG&gt;&lt;SPAN&gt; Enabling &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;panorama&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; mode will utilize system resources for log collection in addition to device management. Ensure your Panorama appliance has sufficient resources.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;3. Changing from Panorama Mode to Logger Mode&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This section describes the transition of a Panorama instance to function solely as a dedicated Log Collector.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Summary of Mode Change: Panorama &amp;gt; Logger&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Configuration lost (Logger mode doesn't utilize Device Group/Template configurations).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Logs lost.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;There is no officially supported method to retain these logs; attempting to manipulate disks is not supported.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Ensure you have backed up your Panorama configuration if you might need to revert or reference it later, as the configuration relevant to management will be lost.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Considerations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Loss of Management Configuration:&lt;/STRONG&gt;&lt;SPAN&gt; Switching to Logger mode will erase the management configuration (Device Groups, Templates, etc.). This action is irreversible without restoring from a backup.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Loss of Local Logs:&lt;/STRONG&gt;&lt;SPAN&gt; Any logs currently stored locally on the Panorama will likely be lost during this transition.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Dedicated Logging Role:&lt;/STRONG&gt;&lt;SPAN&gt; After this change, the system will only function as a log collector and will not manage firewalls. You will need a separate Panorama instance for management.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;4. Summary Table&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Current Mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;New Mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Pre-requisites&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- All managed devices must be assigned to an LCG&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Local Log Collector must not be a member of any LCG&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- No configuration impact&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- 2nd disk of 2TB must be attached (applies to VM appliance only)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- No impact&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Device Management license must be applied&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of Template and DG configuration&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- 2nd disk of 2TB must be attached (applies to VM appliance only)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- No configuration impact&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Must switch to Panorama mode first&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- See above&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Must switch to Panorama mode first&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- See above&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 02 Jun 2025 10:10:56 GMT</pubDate>
    <dc:creator>shv</dc:creator>
    <dc:date>2025-06-02T10:10:56Z</dc:date>
    <item>
      <title>Understanding Panorama System Mode Transitions</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/understanding-panorama-system-mode-transitions/ta-p/1230681</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-06-02 at 3.28.33 PM (2).png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67832iF854CD45D031E9B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-06-02 at 3.28.33 PM (2).png" alt="Screenshot 2025-06-02 at 3.28.33 PM (2).png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This document outlines the various system modes available for Palo Alto Networks &lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;and provides guidance on transitioning between them. &lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;offers flexibility with its different modes: Panorama, Management-Only, and Logger.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reasons for changing system modes might include optimizing resource allocation by separating log collection and management, transitioning to dedicated logging with Logger mode, or simplifying operations to management-only. Each mode serves a specific purpose and knowing the prerequisites and considerations for each transition is essential to avoid data loss and ensure smooth operations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;1. Changing from Panorama Mode to Management-Only Mode&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This section details the process and considerations for moving a Panorama appliance from its default Panorama mode (managing devices and processing their logs) to Management-Only mode (solely for device management).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Summary of Mode Change: Panorama &amp;gt; Management-Only&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;No loss of configuration.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Firewall Logs are lost (as &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;management-only&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; mode disables the Log Collector processes).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;There is no officially supported method to retain these logs; attempting to manipulate disks is not supported.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Log Collector Group Assignment:&lt;/STRONG&gt;&lt;SPAN&gt; All managed firewalls &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;must&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; be assigned to a Log Collector Group. Refer to Palo Alto Networks Knowledge Base article&lt;/SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008Ub7CAE" target="_blank" rel="noopener"&gt; &lt;SPAN&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008Ub7CAE&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;If there are no Log Collector Groups and no Dedicated Log Collectors available, create a “dummy” Log Collector Group and a Dedicated Log Collector and assign managed devices to this temporary Group.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Please note that adding a disconnected Dedicated Log Collector to a Log Collector Group must be done via CLI as it is not possible via GUI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;set log-collector-group {DUMMY_LCG_NAME} logfwd-setting collectors {DUMMY_DLC_SERIAL_NUMBER}&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Example: &lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;set log-collector-group EMPTY_LCG logfwd-setting collectors 1234&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;If there are any disconnected managed devices not assigned to a Log Collector Group, these need to be removed, or assigned to an LCG via CLI as it is not possible to assign a disconnected device to an LCG via GUI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;set log-collector-group {DUMMY_LCG_NAME} logfwd-setting devices {DEVICE_SERIAL_NUMBER}&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="3"&gt;&lt;SPAN&gt;Example:&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt; set log-collector-group BLANK_LCG logfwd-setting devices 4567&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Isolation of Local Log Collectors (LLCs):&lt;/STRONG&gt;&lt;SPAN&gt; Ensure that any Local Log Collectors (running on the Panorama itself) are &lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt; part of any Log Collector Groups. This might require removing the Local Log Collectors from existing Log Collector Groups.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Considerations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Loss of Local Logs:&lt;/STRONG&gt;&lt;SPAN&gt; Switching to Management-Only mode will stop local log collection on Panorama. Ensure you have dedicated Log Collectors in place to handle logging for your managed devices.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;HA Pair Transition:&lt;/STRONG&gt;&lt;SPAN&gt; When dealing with an HA pair, it's recommended to start with the secondary (passive) Panorama. Be aware of potential temporary failovers due to operational mode mismatches.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Potential Communication Issues:&lt;/STRONG&gt;&lt;SPAN&gt; After the mode change, you might encounter temporary communication issues with existing Dedicated Log Collectors (e.g., "ring version mismatch"), which may require a "commit force" on Panorama to resolve.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;2. Changing from Management-Only Mode to Panorama Mode&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This section outlines the considerations for enabling local log collection capabilities on a Panorama that is currently in Management-Only mode.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Summary of Mode Change: Management-Only &amp;gt; Panorama&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;No loss of configuration.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;There are no logs to lose (as &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;management-only&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; mode doesn't collect logs).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;In the case of Virtual Panorama appliances, at least one logging disk of 2TB needs to be attached to the VM before the switch.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Considerations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Enabling Local Logging:&lt;/STRONG&gt;&lt;SPAN&gt; This change will allow the Panorama to act as a Local Log Collector. You will need to configure Log Collector Groups to include the local log collector if you wish for the Panorama to store logs.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Resource Usage:&lt;/STRONG&gt;&lt;SPAN&gt; Enabling &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;panorama&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; mode will utilize system resources for log collection in addition to device management. Ensure your Panorama appliance has sufficient resources.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;3. Changing from Panorama Mode to Logger Mode&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This section describes the transition of a Panorama instance to function solely as a dedicated Log Collector.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Summary of Mode Change: Panorama &amp;gt; Logger&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Configuration lost (Logger mode doesn't utilize Device Group/Template configurations).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Logs lost.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;There is no officially supported method to retain these logs; attempting to manipulate disks is not supported.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Ensure you have backed up your Panorama configuration if you might need to revert or reference it later, as the configuration relevant to management will be lost.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Considerations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Loss of Management Configuration:&lt;/STRONG&gt;&lt;SPAN&gt; Switching to Logger mode will erase the management configuration (Device Groups, Templates, etc.). This action is irreversible without restoring from a backup.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Loss of Local Logs:&lt;/STRONG&gt;&lt;SPAN&gt; Any logs currently stored locally on the Panorama will likely be lost during this transition.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Dedicated Logging Role:&lt;/STRONG&gt;&lt;SPAN&gt; After this change, the system will only function as a log collector and will not manage firewalls. You will need a separate Panorama instance for management.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;4. Summary Table&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Current Mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;New Mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Pre-requisites&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- All managed devices must be assigned to an LCG&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Local Log Collector must not be a member of any LCG&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- No configuration impact&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- 2nd disk of 2TB must be attached (applies to VM appliance only)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- No impact&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Device Management license must be applied&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of Template and DG configuration&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- 2nd disk of 2TB must be attached (applies to VM appliance only)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Loss of logs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- No configuration impact&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Must switch to Panorama mode first&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- See above&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Management-Only&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Logger&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- Must switch to Panorama mode first&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;- See above&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 02 Jun 2025 10:10:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/understanding-panorama-system-mode-transitions/ta-p/1230681</guid>
      <dc:creator>shv</dc:creator>
      <dc:date>2025-06-02T10:10:56Z</dc:date>
    </item>
  </channel>
</rss>

