<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VM series firewalls not sending logs to Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533858#M109924</link>
    <description>&lt;P&gt;Restarting the management process did the trick. I BELIEVE I had done a push to device, though I could be wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bonus question: Do you know if there is a way to automate adding a firewall to collector groups's device log forwarding section? These firewalls can be stood up or down so right now I think I'll have to add/remove them manually if there is a teardown event.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 21:50:33 GMT</pubDate>
    <dc:creator>Verac22</dc:creator>
    <dc:date>2023-03-09T21:50:33Z</dc:date>
    <item>
      <title>VM series firewalls not sending logs to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533757#M109913</link>
      <description>&lt;P&gt;Hello again all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My next hurdle is figuring out why my VM-Series firewalls aren't getting their logs to the panorama server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've checked the following soo far:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Network path between the firewalls and panorama look good. it's allowing ICMP and all TCP.&lt;/LI&gt;
&lt;LI&gt;Managed collectors (local to this panorama an an HA panorama) show green, in sync, green health status.&lt;/LI&gt;
&lt;LI&gt;There's just one collector group with with both of those collectors in it&lt;/LI&gt;
&lt;LI&gt;I've added the VM-series firewalls into the Device log forwarding section on the collector group&lt;/LI&gt;
&lt;LI&gt;In the firewall policies, there is traffic hitting them and the action is set to log and forward to a log forwarding profile&lt;/LI&gt;
&lt;LI&gt;log forwarding profile has objects to forward all traffic and threat logs to panorama.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I'm unaware if I'm issuing any configuration points in the above.&lt;/P&gt;
&lt;P&gt;If I go to the firewall and run a "debug management-server log-collector-agent-status" there are no agents listed. If I run a "show logging-status", I see a variety of collectors but they are all in a "lr - Inactive" state under connection status.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea what I'm missing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 13:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533757#M109913</guid>
      <dc:creator>Verac22</dc:creator>
      <dc:date>2023-03-09T13:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: VM series firewalls not sending logs to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533854#M109923</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275773"&gt;@Verac22&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you run on the Firewall side this command: "show log-collector preference-list"? If it does not return the IP addresses of Log Collectors, I would restart management process of the Firewall. Here is reference&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaGCAS" target="_self"&gt;KB&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you assigned the Firewalls to log collectors did you push the configuration to log collectors after you committed the change in Panorama? Without this step, the configuration will not be applied and logs will not come. Reference Step No.12, point No.8 in the &lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-log-collection/log-collection-deployments/deploy-panorama-with-dedicated-log-collectors" target="_self"&gt;Doc.&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 21:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533854#M109923</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-03-09T21:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: VM series firewalls not sending logs to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533858#M109924</link>
      <description>&lt;P&gt;Restarting the management process did the trick. I BELIEVE I had done a push to device, though I could be wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bonus question: Do you know if there is a way to automate adding a firewall to collector groups's device log forwarding section? These firewalls can be stood up or down so right now I think I'll have to add/remove them manually if there is a teardown event.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 21:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/533858#M109924</guid>
      <dc:creator>Verac22</dc:creator>
      <dc:date>2023-03-09T21:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: VM series firewalls not sending logs to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/534014#M109937</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275773"&gt;@Verac22&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unfortunately, I am not aware of anything outside of steps for regular firewall onboarding in Step No.3, point No.6:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device" target="_self"&gt;Doc&lt;/A&gt;. If I come across something that addresses this, I will re-visit this post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 20:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vm-series-firewalls-not-sending-logs-to-panorama/m-p/534014#M109937</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-03-10T20:50:08Z</dc:date>
    </item>
  </channel>
</rss>

