<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logging to Panorama over a WAN Link in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39332#M28866</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you could also opt to not forward all log, but selectively forward only logs that are important and leave generic logs on the units&lt;/P&gt;&lt;P&gt;you can accomplish this by setting logforwarding for critical and high risk threats, and select only the most important security rules to forward logs to panorama&lt;/P&gt;&lt;P&gt;this could dramatically decrease the total volume of log forwarded to panorama&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Sep 2011 15:48:11 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2011-09-14T15:48:11Z</dc:date>
    <item>
      <title>Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39329#M28863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a remote location that connects back to our corporate office via a WAN Link.&amp;nbsp; At this remote site, we have two clusters of Palo Alto Firewalls that are pretty heavily utilized and produce around 1+ GB of log per day.&amp;nbsp; We are preparing to deploy Panorama at our Corporate location to manage all of our PA firewalls.&amp;nbsp; We would like to send the log data from the firewalls at this remote site to Panorama, but do not want to fill our wan link with this log data.&amp;nbsp; Are there other options of getting this log data back to Panorama?&amp;nbsp; Is it possible to create a log export policy to run overnight and import this log data into Panorama?&amp;nbsp; I know that log data would not be real time in Panorama, but we could still view the log data on the firewall gateways themselves for troubleshooting purposes.&amp;nbsp; Also, with a 25 node license, can we install multiple instances of Panorama (1 at Corporate and 1 at the remote site) as long as we dont exceed the total 25 node license?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help/input would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 18:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39329#M28863</guid>
      <dc:creator>Milamber</dc:creator>
      <dc:date>2010-09-07T18:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39330#M28864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The PAN device can schedule log export for the traffic and threat log, but Panorama does not allow import of the logs in that format only the logdb.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Regarding multiple instances of Panorama yes, with the understanding that each PAN device can only comunicate with a single instance of Panorama.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Gary S.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 02:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39330#M28864</guid>
      <dc:creator>gsamuels</dc:creator>
      <dc:date>2010-09-08T02:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39331#M28865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;You will need individual licenses for each Panorama you want to use. Only one installation of Panorama is supported per license SKU.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 21:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39331#M28865</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-09-12T21:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39332#M28866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you could also opt to not forward all log, but selectively forward only logs that are important and leave generic logs on the units&lt;/P&gt;&lt;P&gt;you can accomplish this by setting logforwarding for critical and high risk threats, and select only the most important security rules to forward logs to panorama&lt;/P&gt;&lt;P&gt;this could dramatically decrease the total volume of log forwarded to panorama&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 15:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39332#M28866</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-09-14T15:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39333#M28867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi gsamuels,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After exporting logs, do you have any offline viewing tools that can act in the same way in PANOS? (i.e. applying filter for query.) Or is there a tool that convert the exported format back to logdb, so that we can use the log data to create global reports for all sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;JonQ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 17:54:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39333#M28867</guid>
      <dc:creator>jqiu</dc:creator>
      <dc:date>2011-09-15T17:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39334#M28868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon Q,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do not provide a stand alone tool for reading logs, this doesn't mean no tools exist. If for instance you were to redirect logs to an external syslog server you could use your favorite SQL query tools to run reports. You can also use many embedded text editors to just search strings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 16:46:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39334#M28868</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-09-19T16:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logging to Panorama over a WAN Link</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39335#M28869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Phil!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 03:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-to-panorama-over-a-wan-link/m-p/39335#M28869</guid>
      <dc:creator>jqiu</dc:creator>
      <dc:date>2011-09-21T03:36:14Z</dc:date>
    </item>
  </channel>
</rss>

