<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Long term log retention and analysis? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/long-term-log-retention-and-analysis/m-p/17007#M12409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're currently utilizing Panorama sitting on 2TB of SAN-attached disk to retain as many logs as possible. However, even with 2TB of disk, we're not able to reach our stated policy goal of retaining six months of logging data (we log an awful lot of data).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've looked into the scheduled log export facilities available on the 4020s, but it looks like Panorama (at least version 3.0.6) doesn't have an equivalent option. We'd much prefer to back up logs from Panorama to long-term storage, rather than from the individual 4020s. However, the bigger question is how customers perform forensic work on logs that have been taken off the Panorama engine. We're debating setting up another Panorama installation, but how logs would be exported and then reimported into this engine isn't clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm interested in hearing if other organizations have encountered similar issues, and if so what creative solutions they may have developed for longer-term retention and analysis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Apr 2010 20:48:05 GMT</pubDate>
    <dc:creator>jwherbert</dc:creator>
    <dc:date>2010-04-01T20:48:05Z</dc:date>
    <item>
      <title>Long term log retention and analysis?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/long-term-log-retention-and-analysis/m-p/17007#M12409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're currently utilizing Panorama sitting on 2TB of SAN-attached disk to retain as many logs as possible. However, even with 2TB of disk, we're not able to reach our stated policy goal of retaining six months of logging data (we log an awful lot of data).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've looked into the scheduled log export facilities available on the 4020s, but it looks like Panorama (at least version 3.0.6) doesn't have an equivalent option. We'd much prefer to back up logs from Panorama to long-term storage, rather than from the individual 4020s. However, the bigger question is how customers perform forensic work on logs that have been taken off the Panorama engine. We're debating setting up another Panorama installation, but how logs would be exported and then reimported into this engine isn't clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm interested in hearing if other organizations have encountered similar issues, and if so what creative solutions they may have developed for longer-term retention and analysis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Apr 2010 20:48:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/long-term-log-retention-and-analysis/m-p/17007#M12409</guid>
      <dc:creator>jwherbert</dc:creator>
      <dc:date>2010-04-01T20:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Long term log retention and analysis?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/long-term-log-retention-and-analysis/m-p/17008#M12410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;you may want to investigate using Saw mill or Splunk. These two solutions have been the most popular by far by most of our customers for organizing and archiving logs and generating robust reports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Apr 2010 19:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/long-term-log-retention-and-analysis/m-p/17008#M12410</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-04-05T19:56:41Z</dc:date>
    </item>
  </channel>
</rss>

