<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: My PA-1410  logs for single day, why? how to solve? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598450#M119035</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159497"&gt;@MRamadanAHafiez&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Default to log at session end and evaluate the importance of having the immediate knowledge of a session that is on-going without looking at the session table. The reason only logging at the end of the session is the default is that the session table is an easy way to look at all on-going sessions without looking at the log files themselves. You never really &lt;EM&gt;&lt;STRONG&gt;need &lt;/STRONG&gt;&lt;/EM&gt;logs available solely at the start of the session because that session itself is visible directly in the session table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's limited policies that I will have log-start and log-end enabled, and it's usually just traditionally long-running sessions that I care to track via automation. For example SSH/RDP/SMB are all connections that can be open for a real long time if they are actively passing traffic, but I don't want to have a process to look at &lt;EM&gt;closed &lt;/EM&gt;sessions and &lt;EM&gt;on-going &lt;/EM&gt;sessions because I'd have to develop that automation around two different sets of data. I personally just find it easier to enable log-start and have my automation generate alerts based on the traffic logs instead of both the logs and the session table to keep things a bit cleaner. If I was running into issues with log retention then I would personally likely take the time to adjust my automation to actively look at the session table in addition to just the logs themselves.&lt;/P&gt;
&lt;P&gt;I don't see &lt;EM&gt;too &lt;/EM&gt;much use in generating logs at session start unless I'm actively monitoring those connections. If someone asks you to troubleshoot something that is on-going it's as easy as going into the session table instead of the traffic logs to see how the traffic is being processed. You can adjust alerting to account for not having logs at session start, you can adjust automation to look at the session table instead of the logs, and just in general there's few session that I feel the need to know &lt;EM&gt;immediately &lt;/EM&gt;as soon as the session kicks off that isn't satisfied by the session table. &lt;/P&gt;</description>
    <pubDate>Sat, 21 Sep 2024 06:44:01 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-09-21T06:44:01Z</dc:date>
    <item>
      <title>My PA-1410  logs for single day, why? how to solve?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598428#M119029</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;My new PA-1410 logging is not more than a single day when checking the traffic logs.&lt;/P&gt;
&lt;P&gt;Previously I had PA-3220 I could checked months of logs.&lt;/P&gt;
&lt;P&gt;whats wrong here in the PA-1410 loggin settings?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;manager@PA-1410-Main(active)&amp;gt; show system logdb-quota&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quotas:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system: 4.00%, 0.726 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; config: 4.00%, 0.726 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alarm: 3.00%, 0.544 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; appstat: 4.00%, 0.726 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hip-reports: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; traffic: 29.00%, 5.263 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; threat: 15.00%, 2.722 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; trsum: 7.00%, 1.270 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlytrsum: 3.00%, 0.544 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailytrsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklytrsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; urlsum: 2.00%, 0.363 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlyurlsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailyurlsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklyurlsum: 0.75%, 0.136 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; thsum: 2.00%, 0.363 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlythsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailythsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklythsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userid: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; iptag: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; application-pcaps: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; extpcap: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp; debug-filter-pcaps: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dlp-logs: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hipmatch: 3.00%, 0.544 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gtp: 2.00%, 0.363 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gtpsum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlygtpsum: 0.75%, 0.136 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailygtpsum: 0.75%, 0.136 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklygtpsum: 0.75%, 0.136 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; auth: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sctp: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sctpsum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlysctpsum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailysctpsum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklysctpsum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; decryption: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; desum: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hourlydesum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dailydesum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weeklydesum: 0.00%, 0.000 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; globalprotect: 1.00%, 0.181 GB Expiration-period: 0 days&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disk usage:&lt;/P&gt;
&lt;P&gt;traffic: Logs and Indexes: 4.3G Current Retention: 1 days&lt;/P&gt;
&lt;P&gt;threat: Logs and Indexes: 2.0G Current Retention: 2 days&lt;/P&gt;
&lt;P&gt;system: Logs and Indexes: 254M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;config: Logs and Indexes: 132M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;alarm: Logs and Indexes: 13M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;trsum: Logs and Indexes: 1.4G Current Retention: 2 days&lt;/P&gt;
&lt;P&gt;hourlytrsum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;dailytrsum: Logs and Indexes: 197M Current Retention: 2 days&lt;/P&gt;
&lt;P&gt;weeklytrsum: Logs and Indexes: 200M Current Retention: 12 days&lt;/P&gt;
&lt;P&gt;thsum: Logs and Indexes: 163M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;hourlythsum: Logs and Indexes: 178M Current Retention: 27 days&lt;/P&gt;
&lt;P&gt;dailythsum: Logs and Indexes: 137M Current Retention: 27 days&lt;/P&gt;
&lt;P&gt;weeklythsum: Logs and Indexes: 32M Current Retention: 26 days&lt;/P&gt;
&lt;P&gt;appstatdb: Logs and Indexes: 234M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;userid: Logs and Indexes: 147M Current Retention: 2 days&lt;/P&gt;
&lt;P&gt;iptag: Logs and Indexes: 57M Current Retention: 16 days&lt;/P&gt;
&lt;P&gt;hipmatch: Logs and Indexes: 126M Current Retention: 27 days&lt;/P&gt;
&lt;P&gt;hip-reports: Logs and Indexes:&amp;nbsp; Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;extpcap: Logs and Indexes: 98M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;urlsum: Logs and Indexes: 383M Current Retention: 1 days&lt;/P&gt;
&lt;P&gt;hourlyurlsum: Logs and Indexes: 195M Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;dailyurlsum: Logs and Indexes: 187M Current Retention: 2 days&lt;/P&gt;
&lt;P&gt;weeklyurlsum: Logs and Indexes: 164M Current Retention: 12 days&lt;/P&gt;
&lt;P&gt;gtp: Logs and Indexes: 13M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;gtpsum: Logs and Indexes: 13M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;hourlygtpsum: Logs and Indexes: 296K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;dailygtpsum: Logs and Indexes: 288K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;weeklygtpsum: Logs and Indexes: 48K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;auth: Logs and Indexes: 113M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;sctp: Logs and Indexes: 13M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;sctpsum: Logs and Indexes: 13M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;hourlysctpsum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;dailysctpsum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;weeklysctpsum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;decryption: Logs and Indexes: 148M Current Retention: 2 days&lt;/P&gt;
&lt;P&gt;desum: Logs and Indexes: 191M Current Retention: 21 days&lt;/P&gt;
&lt;P&gt;hourlydesum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;dailydesum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;weeklydesum: Logs and Indexes: 8.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;globalprotect: Logs and Indexes: 139M Current Retention: 35 days&lt;/P&gt;
&lt;P&gt;application: Logs and Indexes: 161M Current Retention: 24 days&lt;/P&gt;
&lt;P&gt;filters: Logs and Indexes: 4.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;dlp: Logs and Indexes: 4.0K Current Retention: 0 days&lt;/P&gt;
&lt;P&gt;hip_report_base: Logs and Indexes: 2.7M Current Retention: N/A&lt;/P&gt;
&lt;P&gt;wildfire: Logs and Indexes: 48K Current Retention: N/A&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Space reserved for cores:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0MB&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 19:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598428#M119029</guid>
      <dc:creator>MRamadanAHafiez</dc:creator>
      <dc:date>2024-09-20T19:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: My PA-1410  logs for single day, why? how to solve?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598446#M119033</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159497"&gt;@MRamadanAHafiez&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So good news and bad news. The good news is that nothing is wrong with your PA-1410 and it's functioning as designed and from what you've shared you've successfully allocated the entire disk available for logs. The bad news is that nothing is wrong and there's nothing you can readily do to just fix this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your PA-1410 has a &lt;STRONG&gt;&lt;EM&gt;much smaller &lt;/EM&gt;&lt;/STRONG&gt;disk than what your PA-3220 did, which is just a consequence of moving down in chassis. The PA-3220 has a 240GB SSD where your PA-1410 only has 128GB available. That translates by default to your PA-1410 having 30GB available for logs while your PA-3220 had over quadruple that at 132GB.&lt;/P&gt;
&lt;P&gt;The size difference doesn't account for the drop from months to a single day however, but your traffic log size that you have indicated is essentially not going to allow for much more than a days worth of logs. With that large of a difference I would be trying to see if you're logging something that you maybe weren't previously that is extremely chatty, for example DNS traffic if you weren't logging that previously.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since simply replacing hardware is a poor replacement to a logging retention issue, your cheapest path forward is going to be setting up a SIEM for long-term log storage. Something like Graylog can be had for free as long as you have a system to run it and the storage to actually store the logs long-term. I'd personally try adjusting some of your allocation to get a longer traffic log retention on the PA-1410 itself just because that makes troubleshooting a bit easier, but ultimately you'll have to shift your long-term logs somewhere and get used to searching things a bit differently.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 03:54:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598446#M119033</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-09-21T03:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: My PA-1410  logs for single day, why? how to solve?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598449#M119034</link>
      <description>&lt;P&gt;Thanx Bro &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; I felt like I got stuck in this small box.&lt;/P&gt;
&lt;P&gt;About SIEM, I already have deployed elastics with palaoto logs forwarded to it. and according to you, some logging in the policies must be done then.&lt;/P&gt;
&lt;P&gt;By the way, one last ques. Do you recommed to set the log to "Log ar session start, or log at session end" ? as long as we won;t be able to set to both in most of the policies.&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 06:28:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598449#M119034</guid>
      <dc:creator>MRamadanAHafiez</dc:creator>
      <dc:date>2024-09-21T06:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: My PA-1410  logs for single day, why? how to solve?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598450#M119035</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159497"&gt;@MRamadanAHafiez&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Default to log at session end and evaluate the importance of having the immediate knowledge of a session that is on-going without looking at the session table. The reason only logging at the end of the session is the default is that the session table is an easy way to look at all on-going sessions without looking at the log files themselves. You never really &lt;EM&gt;&lt;STRONG&gt;need &lt;/STRONG&gt;&lt;/EM&gt;logs available solely at the start of the session because that session itself is visible directly in the session table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's limited policies that I will have log-start and log-end enabled, and it's usually just traditionally long-running sessions that I care to track via automation. For example SSH/RDP/SMB are all connections that can be open for a real long time if they are actively passing traffic, but I don't want to have a process to look at &lt;EM&gt;closed &lt;/EM&gt;sessions and &lt;EM&gt;on-going &lt;/EM&gt;sessions because I'd have to develop that automation around two different sets of data. I personally just find it easier to enable log-start and have my automation generate alerts based on the traffic logs instead of both the logs and the session table to keep things a bit cleaner. If I was running into issues with log retention then I would personally likely take the time to adjust my automation to actively look at the session table in addition to just the logs themselves.&lt;/P&gt;
&lt;P&gt;I don't see &lt;EM&gt;too &lt;/EM&gt;much use in generating logs at session start unless I'm actively monitoring those connections. If someone asks you to troubleshoot something that is on-going it's as easy as going into the session table instead of the traffic logs to see how the traffic is being processed. You can adjust alerting to account for not having logs at session start, you can adjust automation to look at the session table instead of the logs, and just in general there's few session that I feel the need to know &lt;EM&gt;immediately &lt;/EM&gt;as soon as the session kicks off that isn't satisfied by the session table. &lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 06:44:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/598450#M119035</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-09-21T06:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: My PA-1410  logs for single day, why? how to solve?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/999864#M122689</link>
      <description>&lt;P&gt;That does nto explain why his retention period for Traffic is set to 1 day, it should be zero, the default and the log should roll over as it fills.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 15:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/my-pa-1410-logs-for-single-day-why-how-to-solve/m-p/999864#M122689</guid>
      <dc:creator>JimCox</dc:creator>
      <dc:date>2024-12-30T15:50:38Z</dc:date>
    </item>
  </channel>
</rss>

