<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Questions) Missing Panorama Log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507330#M105727</link>
    <description>&lt;P&gt;Thank you for reply and your comment&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139416"&gt;@future&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sure you must have a good reason to keep both "Log at Session Start" and "Log at Session End" enabled. Just in case here is a KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt5CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt5CAC&lt;/A&gt;&amp;nbsp;where Palo Alto does not recommend to keep both options enabled unless you are performing a troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you perform the upgrade to 9.1.14 and you are still experiencing an issue where logs are available on Firewall locally, but missing in Panorama, then if you see any Fails in the output: "debug log-collector log-collection-stats show incoming-logs | match Fails" there are at least 2 possible root causes I can think of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- If you have distributed environment with multiple log collectors and there is a latency between log collectors more than 10ms, this might result log loss. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- High logging rate from Firewall side that will cause failing to write logs to disk. This will however require more investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2022 05:55:29 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2022-06-30T05:55:29Z</dc:date>
    <item>
      <title>Questions) Missing Panorama Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507048#M105724</link>
      <description>&lt;P&gt;When creating the Security Policy Rule, 'Log at Session Start/End' was all selected as Actions.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy Actions.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42043i46BDC2CBA5575602/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Policy Actions.png" alt="Policy Actions.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;After this, when I check the log in Panorama, only the End Log is visible and the Start Log is not visible.&lt;BR /&gt;Also, sometimes this logs are not visible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Panorama, there are cases where the log cannot be seen or some logs (Session Start) are not visible like this.&lt;BR /&gt;What causes this to happen?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could there be a lot of traffic logs and some logs might be missing from Panorama?&lt;BR /&gt;Has anyone had a similar experience?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 11:45:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507048#M105724</guid>
      <dc:creator>future</dc:creator>
      <dc:date>2022-06-29T11:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Questions) Missing Panorama Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507082#M105725</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139416"&gt;@future&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;troubleshooting Panorama missing logs is complex and requires more input from your side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First thing, could you confirm what PAN-OS version you are running on Firewall? If you are in 9.1 release, then I would recommend upgrade to 9.1.14. In this version there is a bug fix:&amp;nbsp;PAN-185616&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1656507414174.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42048iA865540FF98E5241/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1656507414174.png" alt="PavelK_0-1656507414174.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues/pan-os-9-1-14-addressed-issues" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues/pan-os-9-1-14-addressed-issues&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I confirmed with TAC that this is not only limited to syslog, but also affects sending logs to Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you also check Panorama log collector side to confirm from CLI whether there are any Fails:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;debug log-collector log-collection-stats show incoming-logs | match Fails&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If the number of Fails is anything other than 0, this indicates that some logs are failing to be written to disks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you also confirm what PAN-OS version you are running on Panorama and whether you are using dedicated log collectors or local log collector.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 13:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507082#M105725</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-06-29T13:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Questions) Missing Panorama Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507293#M105726</link>
      <description>&lt;P&gt;Thanks for the very kind reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will check further base your advice.&lt;BR /&gt;I was impressed by the positive and complete response.&lt;BR /&gt;Thank you very much.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After additional confirmation, we will deliver happy news when it is complete.&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 01:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507293#M105726</guid>
      <dc:creator>future</dc:creator>
      <dc:date>2022-06-30T01:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Questions) Missing Panorama Log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507330#M105727</link>
      <description>&lt;P&gt;Thank you for reply and your comment&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139416"&gt;@future&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sure you must have a good reason to keep both "Log at Session Start" and "Log at Session End" enabled. Just in case here is a KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt5CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clt5CAC&lt;/A&gt;&amp;nbsp;where Palo Alto does not recommend to keep both options enabled unless you are performing a troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you perform the upgrade to 9.1.14 and you are still experiencing an issue where logs are available on Firewall locally, but missing in Panorama, then if you see any Fails in the output: "debug log-collector log-collection-stats show incoming-logs | match Fails" there are at least 2 possible root causes I can think of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- If you have distributed environment with multiple log collectors and there is a latency between log collectors more than 10ms, this might result log loss. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- High logging rate from Firewall side that will cause failing to write logs to disk. This will however require more investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 05:55:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-missing-panorama-log/m-p/507330#M105727</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-06-30T05:55:29Z</dc:date>
    </item>
  </channel>
</rss>

