<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local Logging configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/554675#M112691</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have VM Firewalls which are being managed locally. Not via Panorama. So if i start sending the logs to Syslog server will that be visible in Monitor tab?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
    <pubDate>Tue, 22 Aug 2023 12:06:08 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2023-08-22T12:06:08Z</dc:date>
    <item>
      <title>Local Logging configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/549764#M112141</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;By default i see the logging configuration it is pointing to Panorama. But we are not managing the firewall using Panorama, we are managing it locally. Can we configure the logging to be logged locally only like live logs max of 100mb should be stored for troubleshooting purpose and then auto delete.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 09:25:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/549764#M112141</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-07-18T09:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Local Logging configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/549825#M112152</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Did you by chance purchase a PA-410? While this can be utilized without Panorama, that isn't the intent of that hardware. It also has no local logging capabilities from a dataplane aspect. It has very limited logging capabilities for management logs (system/configuration) and absolutely nothing else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any other piece of hardware it wouldn't default to Panorama nor would it be configured to send logs to Panorama by default. You would control that via log forwarding, and you can configure your log retention under Device -&amp;gt; Setup -&amp;gt; Management -&amp;gt; Logging and Reporting Settings if you wanted to set the quata and the maximum retention from a length aspect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 13:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/549825#M112152</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-07-18T13:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Local Logging configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/550894#M112251</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Here's a general outline of the steps you can follow:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Access the Firewall Management Interface: Log in to the firewall management interface using your preferred method, such as a web browser or SSH.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Navigate to Logging Settings: Once logged in, navigate to the logging settings section. The exact location of this setting may vary depending on the firewall model and software version you are using. Look for options related to logging and log settings.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Change Logging Destination: In the logging settings, you should find an option to specify the logging destination. Switch the destination from Panorama to local storage or a local syslog server.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Configure Local Log Size and Retention: You can set the maximum size of the local log file to limit it to 100 MB, as per your requirement. Additionally, you can configure the log retention settings to automatically delete old logs once they reach a certain age or when the log file is full.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Save and Apply Changes: After making the necessary adjustments to the logging settings, save the changes and apply them to the firewall.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope it helps you.&lt;/P&gt;
&lt;P&gt;(&lt;A href="http://bit.ly/3ZVJ3c0" target="_self"&gt;&lt;SPAN&gt;CCSP Training&lt;/SPAN&gt;&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 10:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/550894#M112251</guid>
      <dc:creator>stevediaz</dc:creator>
      <dc:date>2023-07-25T10:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Local Logging configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/554675#M112691</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have VM Firewalls which are being managed locally. Not via Panorama. So if i start sending the logs to Syslog server will that be visible in Monitor tab?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 12:06:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/554675#M112691</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-08-22T12:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Local Logging configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/554702#M112697</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you sent the logs to a syslog server they would be visible via the syslog server, not through the monitor tab. It's a work around primarily for people that mistakenly purchase a PA-410 without realizing that it doesn't store any dataplane logs locally and is meant to be used with Panorama, when they really should have purchased a PA-415.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're using a VM series device that leads me to two possible scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The VM isn't licensed and this is expected. You won't get any logs if the device isn't licensed.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You don't have logging enabled on any of our security policies actually allowing traffic to pass. This is&amp;nbsp;&lt;EM&gt;unlikely&amp;nbsp;&lt;/EM&gt;because you'd have to actually try to do that, but certainly possible to do so.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 22 Aug 2023 14:32:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/554702#M112697</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-08-22T14:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Local Logging configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/593743#M118181</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As mentioned PA-410 doesn't store any dataplane logs locally, so the best alternative for customer that really interested to purchase this model is to make sure firewall need to be managed by Panorama (customer plan to replace 20 units existing firewall).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is my understanding correct?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 07:52:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-logging-configuration/m-p/593743#M118181</guid>
      <dc:creator>nuranisnadiah</dc:creator>
      <dc:date>2024-08-01T07:52:33Z</dc:date>
    </item>
  </channel>
</rss>

