<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question Regarding Traffic Log DB Quota in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39859#M29232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stefan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the format of the exported log? Can it be viewed by a simple text editor? I managed to export some of the logdb and tried to open it, but the content seems like a binary files. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Jan 2013 02:54:01 GMT</pubDate>
    <dc:creator>anzhari_p</dc:creator>
    <dc:date>2013-01-30T02:54:01Z</dc:date>
    <item>
      <title>Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39854#M29227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On of our customer, BRI, they found a system alarm which said "traffic log database exceed alarm threshold". Here's the screenshot: &lt;/P&gt;&lt;P&gt;&lt;IMG alt="003.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5365_003.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Here's the log quota settings on their box: &lt;/P&gt;&lt;P&gt; &lt;IMG alt="001.PNG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5362_001.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="002.PNG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5363_002.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Here's their real disk usage: &lt;/P&gt;&lt;P&gt; &lt;IMG alt="004.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5364_004.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The question is, what will happen if the traffic log db exceed its threshold? I know from PAN support that if the traffic db exceed tha quota, it will be purged, but I don't know by purged, does that means the whole db is deleted, or the oldest traffic log entry got deleted? Or is it the newest log entry that will got deleted, so there'll be no newer traffic log entry, and the logging stopped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; And by any chance, is it possible to export these log db outside? I managed to re-read the admin guide also and didn't seems to find any clue regarding these. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks before. :smileygrin:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2013 04:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39854#M29227</guid>
      <dc:creator>anzhari_p</dc:creator>
      <dc:date>2013-01-26T04:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39855#M29228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The purging mechanism works as follows. The quota is checked each time a logdb file is rotated. If the quota threshold is violated then we start deleting logs starting from the oldest until the threshold is no longer exceeded. To see how often the logdb file is rotating, you can review the ms.log file for the following entry "Initing log file with version".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer the logdb export question: There is an option to export logs via ftp found in Device -&amp;gt; Scheduled Log Export&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps clear any doubts. Please let me know if I can help clarify further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2013 05:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39855#M29228</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-01-26T05:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39856#M29229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to export through &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Device -&amp;gt; Scheduled Log Export&lt;/SPAN&gt;, and it seems that it only export the last day traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I intend to backup the whole log, from the very oldest. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Is it possible to do that?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2013 07:27:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39856#M29229</guid>
      <dc:creator>anzhari_p</dc:creator>
      <dc:date>2013-01-26T07:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39857#M29230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to export the entire logdb on 5.0.2 successfully with the following command:&lt;/P&gt;&lt;P&gt;&amp;gt; scp export logdb to root@172.18.32.143:/root/logbackup/firewall-logs.tgz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternatively you can export each log type in csv format:&lt;/P&gt;&lt;P&gt;&amp;gt; scp export log traffic start-time equal 2013/01/12@00:00:00 end-time equal 2013/01/26@00:00:00 to root@172.18.32.143:/root/logbackup/logger.csv&lt;/P&gt;&lt;P&gt;root@172.18.32.143's password:&lt;/P&gt;&lt;P&gt;Marking log as exported successfully...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The downside to csv export is that a start and end time must be specified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can view the oldest log for each log type with command:&lt;/P&gt;&lt;P&gt;&amp;gt; show log traffic direction equal forward &lt;/P&gt;&lt;P&gt;Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; App&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Src Port&amp;nbsp;&amp;nbsp; Source&lt;/P&gt;&lt;P&gt;Rule&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; To&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst Port&amp;nbsp;&amp;nbsp; Destination&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Src User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst User&lt;/P&gt;&lt;P&gt;===============================================================================&lt;/P&gt;&lt;P&gt;2013/01/13 14:10:55 web-browsing&amp;nbsp;&amp;nbsp;&amp;nbsp; l3-trust&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 64728&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.18.39.146&lt;/P&gt;&lt;P&gt;webtraffic&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; allow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; l3-dmz&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8080&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.18.38.141&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 01:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39857#M29230</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-01-27T01:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39858#M29231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a good doc on the alarm you mentioned &lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2437"&gt;https://live.paloaltonetworks.com/docs/DOC-2437&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It also explains when the logs are purged&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers your question.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 00:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39858#M29231</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-01-28T00:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39859#M29232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stefan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the format of the exported log? Can it be viewed by a simple text editor? I managed to export some of the logdb and tried to open it, but the content seems like a binary files. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 02:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39859#M29232</guid>
      <dc:creator>anzhari_p</dc:creator>
      <dc:date>2013-01-30T02:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Question Regarding Traffic Log DB Quota</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39860#M29233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The logs exported with 'scp export logdb' are stored using custom compression to help achieve efficient storage. While the logs cannot be viewed, the db can be imported into another PanOS system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is required to export the logs and view them, I would recommend using the 'scp export log traffic' option. Alternatively, you could use the XML API to retrieve the logs in xml form. For more information on API(Section 2.8 Retrieving Logs): &lt;A __default_attr="3576" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 04:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-traffic-log-db-quota/m-p/39860#M29233</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-01-30T04:47:44Z</dc:date>
    </item>
  </channel>
</rss>

