<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama with log collectors in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-with-log-collectors/m-p/449540#M100953</link>
    <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155683"&gt;@RobertShawver&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on my experience, the logs from Firewall to Panorama are sent almost instantly. Under normal circumstances there should not be a&amp;nbsp; significant time gap between logs on Firewall and Panorama. In my case, I can see logs in Panorama within a few minutes. If you see this issue, could you check the output on log collector from this command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;debug log-collector log-collection-stats show incoming-logs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see any value than 0 under:&amp;nbsp;&lt;STRONG&gt;Fails&lt;/STRONG&gt;, this might indicate an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have multiple log collectors ensure that there is latency less than 10ms between each log collector. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you also check the logging rate and health of Elastic Search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;show log-collector-es-cluster health&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;show log-collector detail | match logs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you also make sure that Firewall and Panorama/Log Collector are using the same time zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding syslog exporting from Panorama to 3d party server, I can see some time gap which varies through out the day. Likely depending on load. I have not found any good way to troubleshoot /debug it to narrow down a root cause. Every time, I saw that server does not get any data, i took a pcap on log collector to confirm it is being sent by log collector or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Nov 2021 00:37:24 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-11-26T00:37:24Z</dc:date>
    <item>
      <title>Panorama with log collectors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-with-log-collectors/m-p/449279#M100915</link>
      <description>&lt;P&gt;Here is the set up.&amp;nbsp; Palo FW HA pairs send logs to Panorama and Log Collectors.&amp;nbsp; Log Collectors send logs to l&lt;SPAN&gt;ong term archival (LTA) such as LogRhythm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is the issue, long term storage is not seeing the latest logs.&amp;nbsp; I guess what I don't understand is the timing.&amp;nbsp; When/how often are logs sent from the FW's to Panorama/Loggers and then when/how often do the Loggers send them off to LTA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I get that logs may roll on Panorama based on disk size, but was under the impression that latest logs should be at least reasonably close if I search for a recent for events on Panorama traffic logs and LTA.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 17:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-with-log-collectors/m-p/449279#M100915</guid>
      <dc:creator>RobertShawver</dc:creator>
      <dc:date>2021-11-24T17:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama with log collectors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-with-log-collectors/m-p/449540#M100953</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155683"&gt;@RobertShawver&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on my experience, the logs from Firewall to Panorama are sent almost instantly. Under normal circumstances there should not be a&amp;nbsp; significant time gap between logs on Firewall and Panorama. In my case, I can see logs in Panorama within a few minutes. If you see this issue, could you check the output on log collector from this command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;debug log-collector log-collection-stats show incoming-logs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see any value than 0 under:&amp;nbsp;&lt;STRONG&gt;Fails&lt;/STRONG&gt;, this might indicate an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have multiple log collectors ensure that there is latency less than 10ms between each log collector. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you also check the logging rate and health of Elastic Search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;show log-collector-es-cluster health&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;show log-collector detail | match logs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you also make sure that Firewall and Panorama/Log Collector are using the same time zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding syslog exporting from Panorama to 3d party server, I can see some time gap which varies through out the day. Likely depending on load. I have not found any good way to troubleshoot /debug it to narrow down a root cause. Every time, I saw that server does not get any data, i took a pcap on log collector to confirm it is being sent by log collector or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 00:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-with-log-collectors/m-p/449540#M100953</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-11-26T00:37:24Z</dc:date>
    </item>
  </channel>
</rss>

