<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log retention days in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/511536#M1061</link>
    <description>&lt;P&gt;I have the same issue.&amp;nbsp; Panorama 10.1.5 accepting logs from a number of gateways (most being 9.1.13).&amp;nbsp; Threat log allocation, for example, is 64GB. Expiration Period is 90 days.&amp;nbsp; However the logdb-usage command lists 'Current Retention' as 12 days.&amp;nbsp; &amp;nbsp;64GB should be enough for millions of log entries allowing for at least 90 days.&amp;nbsp; &amp;nbsp; If i export the entire 12 days of threat logs, that is only 80,000 entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA tech i spoke with suspects the allocated space is clogged up with indexes rather than with actual logs. However he is not yet sure how to check.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2022 08:44:51 GMT</pubDate>
    <dc:creator>JimMcGrady</dc:creator>
    <dc:date>2022-08-11T08:44:51Z</dc:date>
    <item>
      <title>log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/475081#M810</link>
      <description>&lt;P&gt;Hi we have 2 panorama and it has virtual disks for log-collector.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I have checked log-collector-es-cluster health and it is green.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 collector-group and 2 log-collectors&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i run cli&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show system logdb-quota&lt;/STRONG&gt; at the active panorama , i get result as below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I understand expiration-period is 30 days , but I can't see more than 16 days&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it disk volume issue ? IMHO , it looks overwrite traffic log older than 16 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quotas:&lt;BR /&gt;system: 8.00%, 1.072 GB Expiration-period: 7 days&lt;BR /&gt;config: 8.00%, 1.072 GB Expiration-period: 7 days&lt;BR /&gt;hip-reports: 1.00%, 0.134 GB Expiration-period: 0 days&lt;BR /&gt;appstat: 5.00%, 0.670 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;BR /&gt;system: Logs and Indexes: 844.9MB Current Retention: 7 days&lt;BR /&gt;config: Logs and Indexes: 28.8MB Current Retention: 7 days&lt;BR /&gt;appstatdb: Logs and Indexes: 691.5MB Current Retention: 20 days&lt;BR /&gt;hip-reports: Logs and Indexes: 0 Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;Slot:0&lt;BR /&gt;Quotas:&lt;BR /&gt;detailed: 60.00%, 282 GB Expiration-period: 30 days&lt;BR /&gt;summary: 30.00%, 141 GB Expiration-period: 30 days&lt;BR /&gt;infra_audit: 5.00%, 24 GB Expiration-period: 30 days&lt;BR /&gt;platform: 0.10%, 0 GB Expiration-period: 30 days&lt;BR /&gt;external: 0.10%, 0 GB Expiration-period: 30 days&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;BR /&gt;detailed: Logs: 137161 MB, Current Retention: 14 days&lt;BR /&gt;summary: Logs: 21456 MB, Current Retention: 27 days&lt;BR /&gt;infra_audit: Logs: 1425 MB, Current Retention: 21 days&lt;BR /&gt;platform: Logs: 0 MB, Current Retention: 0 days&lt;BR /&gt;external: Logs: 0 MB, Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;Slot:1&lt;BR /&gt;Quotas:&lt;BR /&gt;detailed: 60.00%, 282 GB Expiration-period: 30 days&lt;BR /&gt;summary: 30.00%, 141 GB Expiration-period: 30 days&lt;BR /&gt;infra_audit: 5.00%, 24 GB Expiration-period: 30 days&lt;BR /&gt;platform: 0.10%, 0 GB Expiration-period: 30 days&lt;BR /&gt;external: 0.10%, 0 GB Expiration-period: 30 days&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;BR /&gt;detailed: Logs: 137103 MB, Current Retention: 14 days&lt;BR /&gt;summary: Logs: 22017 MB, Current Retention: 27 days&lt;BR /&gt;infra_audit: Logs: 1403 MB, Current Retention: 21 days&lt;BR /&gt;platform: Logs: 0 MB, Current Retention: 0 days&lt;BR /&gt;external: Logs: 0 MB, Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;Slot:2&lt;BR /&gt;Quotas:&lt;BR /&gt;detailed: 60.00%, 282 GB Expiration-period: 30 days&lt;BR /&gt;summary: 30.00%, 141 GB Expiration-period: 30 days&lt;BR /&gt;infra_audit: 5.00%, 24 GB Expiration-period: 30 days&lt;BR /&gt;platform: 0.10%, 0 GB Expiration-period: 30 days&lt;BR /&gt;external: 0.10%, 0 GB Expiration-period: 30 days&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;BR /&gt;detailed: Logs: 137118 MB, Current Retention: 14 days&lt;BR /&gt;summary: Logs: 21723 MB, Current Retention: 27 days&lt;BR /&gt;infra_audit: Logs: 1401 MB, Current Retention: 21 days&lt;BR /&gt;platform: Logs: 0 MB, Current Retention: 0 days&lt;BR /&gt;external: Logs: 0 MB, Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;Space reserved for cores: 0MB&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 21:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/475081#M810</guid>
      <dc:creator>JeffKim</dc:creator>
      <dc:date>2022-03-23T21:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484116#M871</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quotas:&lt;BR /&gt;detailed: 60.00%, 282 GB Expiration-period: 30 days&lt;BR /&gt;...&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;BR /&gt;detailed: Logs: 137161 MB, Current Retention: 14 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here "&lt;SPAN&gt;Expiration-period: 30 days" means the Max Day set fort the specific kind of log&amp;nbsp; ”detailed logs“ is 30 days, if a detailed log is older than 30 days, Panorama deletes it. If you don't set a "Max Day", then Panorama only deletes the old logs when the disk is full and new logs must be written. “Current Retention: 14 days” means the oldest detailed logs on the disk is 14 days old. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;If the device is working fine, wait for a few moredays and you should be able to see&amp;nbsp;"Expiration-period: 30 days" and also “Current Retention: 30 days”&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rxie_2-1651485024984.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40745i7C441F3880268E9C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="rxie_2-1651485024984.png" alt="rxie_2-1651485024984.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rxie_3-1651485453263.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40746iB80FE29D7C754084/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="rxie_3-1651485453263.png" alt="rxie_3-1651485453263.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 09:57:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484116#M871</guid>
      <dc:creator>rxie</dc:creator>
      <dc:date>2022-05-02T09:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484177#M872</link>
      <description>&lt;P&gt;Thanks Rxie ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case of mine , I have never seen&amp;nbsp; over than 16 days .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Slot:2&lt;BR /&gt;Quotas:&lt;BR /&gt;detailed: 60.00%, 282 GB Expiration-period: 30 days&lt;BR /&gt;summary: 30.00%, 141 GB Expiration-period: 30 days&lt;BR /&gt;infra_audit: 5.00%, 24 GB Expiration-period: 30 days&lt;BR /&gt;platform: 0.10%, 0 GB Expiration-period: 30 days&lt;BR /&gt;external: 0.10%, 0 GB Expiration-period: 30 days&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;BR /&gt;detailed: Logs: 136903 MB, Current Retention: 14 days&lt;BR /&gt;summary: Logs: 22788 MB, Current Retention: 25 days&lt;BR /&gt;infra_audit: Logs: 1488 MB, Current Retention: 1 days&lt;BR /&gt;platform: Logs: 0 MB, Current Retention: 0 days&lt;BR /&gt;external: Logs: 0 MB, Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;Space reserved for cores: 0MB&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/dev/sdb1 1.7T 1.1T 560G 67% /opt/panlogs/ld1&lt;BR /&gt;/dev/sdd1 1.7T 903G 749G 55% /opt/panlogs/ld3&lt;BR /&gt;/dev/sdc1 1.7T 904G 748G 55% /opt/panlogs/ld2&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 15:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484177#M872</guid>
      <dc:creator>JeffKim</dc:creator>
      <dc:date>2022-05-02T15:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484387#M873</link>
      <description>&lt;P&gt;Then seems the device is not working as expected, maybe you can open a case to PA support.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 01:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484387#M873</guid>
      <dc:creator>rxie</dc:creator>
      <dc:date>2022-05-03T01:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484390#M874</link>
      <description>&lt;P&gt;I had submitted case , but they couldn't give me an answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 01:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/484390#M874</guid>
      <dc:creator>JeffKim</dc:creator>
      <dc:date>2022-05-03T01:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/511536#M1061</link>
      <description>&lt;P&gt;I have the same issue.&amp;nbsp; Panorama 10.1.5 accepting logs from a number of gateways (most being 9.1.13).&amp;nbsp; Threat log allocation, for example, is 64GB. Expiration Period is 90 days.&amp;nbsp; However the logdb-usage command lists 'Current Retention' as 12 days.&amp;nbsp; &amp;nbsp;64GB should be enough for millions of log entries allowing for at least 90 days.&amp;nbsp; &amp;nbsp; If i export the entire 12 days of threat logs, that is only 80,000 entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA tech i spoke with suspects the allocated space is clogged up with indexes rather than with actual logs. However he is not yet sure how to check.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 08:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/511536#M1061</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2022-08-11T08:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: log retention days</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/1224408#M2810</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61055"&gt;@JeffKim&lt;/a&gt; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37508"&gt;@JimMcGrady&lt;/a&gt;&amp;nbsp;I hope you are doing well. Any chance that you resolved this concern on the log retention?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 07:13:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log-retention-days/m-p/1224408#M2810</guid>
      <dc:creator>EdmarFrancis</dc:creator>
      <dc:date>2025-03-21T07:13:07Z</dc:date>
    </item>
  </channel>
</rss>

