<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please help with log collectors and collector groups in Panorama mode! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511195#M106288</link>
    <description>&lt;P&gt;Thank you for your time and response,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you link me to the page that showed the collector group formula for the n/2+1? I must have read several pages but never once saw it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If several log collectors are required for the multiple log collectors to work in a single collector group, then the only choice I have is to go with the single collector in a collector group.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 08:21:34 GMT</pubDate>
    <dc:creator>mr_almeida</dc:creator>
    <dc:date>2022-08-08T08:21:34Z</dc:date>
    <item>
      <title>Please help with log collectors and collector groups in Panorama mode!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511100#M106280</link>
      <description>&lt;P&gt;Hello all!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have had a single Panorama appliance running in Panorama mode as a local log collector in its own collector group. Firewall logs are sent to Panorama, and all is working well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We now have procured a second Panorama appliance for HA. Hardware, disks etc., are all the same, and I've successfully set them up in HA, synced and healthy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These two Panorama appliances are in different sites - though there is plenty of bandwidth and a few tens of ms latency between them. Currently, each appliance has only a single 2TB assigned to them. We don't plan to change from this setup or utilise dedicated log collectors anytime soon, and log retention fits within requirements.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bit I am confused about is log collectors and collector groups. Cannot decide whether to have both appliances as either:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Single log collector per collector group&lt;/LI&gt;
&lt;LI&gt;Put the secondary appliance in the same collector group as the primary appliance or multiple collectors in a single collector group.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regarding multiple collectors in a collector group, I have read you can achieve redundancy, increase log retention and exceed logging rates. I am aware you need to check the box for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;enable log redundancy across collectors&lt;/CODE&gt;. I am also mindful that the logging rate is half - so I am not sure how the logging rates are exceeded if this happens?!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding a single collector for each collector group, nothing seems to be mentioned or indicates anything about this. Why would I use this over multiple collectors in a single collector group? I know if the secondary appliance is down or lost, we lose those logs. I also assume you can still set the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Log Forwarding Preferences list&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for both collectors in separate groups?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoping someone in this space can shed some light on what they have done or chime in on what you think!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your time in reading and responding!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 08:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511100#M106280</guid>
      <dc:creator>mr_almeida</dc:creator>
      <dc:date>2022-08-05T08:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with log collectors and collector groups in Panorama mode!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511114#M106283</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121189"&gt;@mr_almeida&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you mentioned that latency is a few tens of milliseconds between each of the Panorama appliance. This could actually be an issue if both Panorama local log collectors are in the same log collector group. The latency between each of the log collector in the same log collector group should not exceed 10 milliseconds. Please have a look at this KB for more details:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmUnCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Second issue I am seeing, if your Panorama is running PAN-OS 10.0 and higher, there is a change in behavior compared to PAN-OS 9.1:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-release-information/changes-to-default-behavior" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-release-information/changes-to-default-behavior&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1659704010809.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43023iE36029C208E9DC0D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1659704010809.png" alt="PavelK_0-1659704010809.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In nutshell, if you have 2 log collectors in a single collector group and one log collector is down, the other log collector will stop working as well. The workaround is either separate each log collector into own collector group or have 3 log collectors inside the same log collector group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given these 2 conditions, I personally feel that options No.1: Single log collector per collector group is better option in your case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 12:59:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511114#M106283</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-08-05T12:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with log collectors and collector groups in Panorama mode!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511195#M106288</link>
      <description>&lt;P&gt;Thank you for your time and response,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you link me to the page that showed the collector group formula for the n/2+1? I must have read several pages but never once saw it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If several log collectors are required for the multiple log collectors to work in a single collector group, then the only choice I have is to go with the single collector in a collector group.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 08:21:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511195#M106288</guid>
      <dc:creator>mr_almeida</dc:creator>
      <dc:date>2022-08-08T08:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with log collectors and collector groups in Panorama mode!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511225#M106293</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121189"&gt;@mr_almeida&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is mentioned in this release note:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-release-information/changes-to-default-behavior" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-release-information/changes-to-default-behavior&lt;/A&gt;&amp;nbsp;(Scroll down to Collector Groups).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding n/2+1, 2 log collectors in a single log collector group will work fine, however keep in mind that in worst case scenario if one log collector goes down, then the remaining one will not be operational until the one that went down comes back online. Unless you experience an outage on one log collector, you will not hit this limitation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 12:31:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-help-with-log-collectors-and-collector-groups-in-panorama/m-p/511225#M106293</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-08-08T12:31:56Z</dc:date>
    </item>
  </channel>
</rss>

