<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic granular filtering for panorama/logging service in log forwarding profile in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/granular-filtering-for-panorama-logging-service-in-log/m-p/417085#M187</link>
    <description>&lt;P&gt;Currently we are managing all firewall from Panorama and configured log forwarding profile to forward logs to panorama/logging service. To enable log forwarding to logging service we have also enabled option to forward logs in cortex data lake in all firewall (device &amp;gt; setup&amp;gt;management &amp;gt; enabled duplicate logging ). On cortex data lake instance we have enabled logging only for URL logs.&lt;/P&gt;&lt;P&gt;have some below query and requirement :&lt;/P&gt;&lt;P&gt;Q1. As we have enabled log forwarding to panorama/logging service for all log types , all logs forwarding to panorama. What about cortex data lake ?. Firewall forwarding only url logs or all logs to cortex data lake ? If all logs forwarding to cortex data lake and we are storing only url logs then it will be unnecessary utilization of our internet bandwidth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q2. Can we forward only url filtering logs only to cortex data lake , same logs should not be forwarded to panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q3 . As we have enabled duplicate logging , additional cortex data lake instance is not helping us to improve log retention as its storing the same logs which on-premise panorama is storing. We need some alternative so that logs will be forwarded either to panorama or cortex data lake to manage logging disk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q4. in addition to my second query (Q3) , currently all four locations firewall is managed via panorama. out of this if we forward two firewall logs only to cortex data lake then we can achieve our requirement , want to know configurational changes and challenges.&lt;/P&gt;&lt;P&gt;I have reviewed cortex data lake admin guide , found below consideration :&lt;/P&gt;&lt;P&gt;- if we disabled duplicate logging option in firewall (device &amp;gt;setup &amp;gt; mgmt &amp;gt;cortex data lake) , any chance of loss of logs of old logs stored in panorama.&lt;/P&gt;&lt;P&gt;- can we onboard panorama managed firewall ? here log will forward to cortex data lake but firewall will be managed by panorama.&lt;/P&gt;&lt;P&gt;Because currently cortex data lake is bind with panorama and through panorama all firewalls were connected to cortex data lake.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 04:48:51 GMT</pubDate>
    <dc:creator>Deepak25</dc:creator>
    <dc:date>2021-07-05T04:48:51Z</dc:date>
    <item>
      <title>granular filtering for panorama/logging service in log forwarding profile</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/granular-filtering-for-panorama-logging-service-in-log/m-p/417085#M187</link>
      <description>&lt;P&gt;Currently we are managing all firewall from Panorama and configured log forwarding profile to forward logs to panorama/logging service. To enable log forwarding to logging service we have also enabled option to forward logs in cortex data lake in all firewall (device &amp;gt; setup&amp;gt;management &amp;gt; enabled duplicate logging ). On cortex data lake instance we have enabled logging only for URL logs.&lt;/P&gt;&lt;P&gt;have some below query and requirement :&lt;/P&gt;&lt;P&gt;Q1. As we have enabled log forwarding to panorama/logging service for all log types , all logs forwarding to panorama. What about cortex data lake ?. Firewall forwarding only url logs or all logs to cortex data lake ? If all logs forwarding to cortex data lake and we are storing only url logs then it will be unnecessary utilization of our internet bandwidth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q2. Can we forward only url filtering logs only to cortex data lake , same logs should not be forwarded to panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q3 . As we have enabled duplicate logging , additional cortex data lake instance is not helping us to improve log retention as its storing the same logs which on-premise panorama is storing. We need some alternative so that logs will be forwarded either to panorama or cortex data lake to manage logging disk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q4. in addition to my second query (Q3) , currently all four locations firewall is managed via panorama. out of this if we forward two firewall logs only to cortex data lake then we can achieve our requirement , want to know configurational changes and challenges.&lt;/P&gt;&lt;P&gt;I have reviewed cortex data lake admin guide , found below consideration :&lt;/P&gt;&lt;P&gt;- if we disabled duplicate logging option in firewall (device &amp;gt;setup &amp;gt; mgmt &amp;gt;cortex data lake) , any chance of loss of logs of old logs stored in panorama.&lt;/P&gt;&lt;P&gt;- can we onboard panorama managed firewall ? here log will forward to cortex data lake but firewall will be managed by panorama.&lt;/P&gt;&lt;P&gt;Because currently cortex data lake is bind with panorama and through panorama all firewalls were connected to cortex data lake.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 04:48:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/granular-filtering-for-panorama-logging-service-in-log/m-p/417085#M187</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-07-05T04:48:51Z</dc:date>
    </item>
  </channel>
</rss>

