<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-3020 log retention period in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134957#M47422</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53677"&gt;@Ernest_James&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ACC also offers the&amp;nbsp;information on 'Rule Usage' :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule Usage" style="width: 756px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7047iF85D5579609A25FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2016-12-29_10-14-18.png" alt="Rule Usage" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Rule Usage&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2016 09:17:01 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2016-12-29T09:17:01Z</dc:date>
    <item>
      <title>PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134776#M47389</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am quite new to Palo Alto and I have some queries regarding the URL filter log retention, before we can generate user activty reports for browsed URLs for more than two weeks old, but now we can only see URL filter logs up to no more than 4 days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What affects the log retention period and how can we generate a month old User Activity report for a specific user if logs are not present anymore.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 06:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134776#M47389</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-28T06:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134783#M47390</link>
      <description>&lt;P&gt;Log retention is affected only by space on disk. When you run out of it PA automaticaly deletes oldest entries in that specific log, whether it's traffic, threat, URL...&lt;/P&gt;&lt;P&gt;You can adjust the reserved space for each type of log in Device -&amp;gt; Setup -&amp;gt; Management tab -&amp;gt; Logging and Reporting Settings&lt;/P&gt;&lt;P&gt;Within the limits of your hard drive capacity of course.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 07:20:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134783#M47390</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-28T07:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134785#M47392</link>
      <description>&lt;P&gt;Hi Santonic, thanks for the response.&lt;/P&gt;&lt;P&gt;So does this means that we suddenly have an huge amount of increase in traffic that cause the retention from more than 2 weeks to just 4days?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also which one of this affects the url filter.&lt;/P&gt;&lt;P&gt;&amp;gt; show system logdb-quota&lt;/P&gt;&lt;P&gt;Quotas:&lt;BR /&gt;system: 4.00%, 3.356 GB&lt;BR /&gt;config: 4.00%, 3.356 GB&lt;BR /&gt;alarm: 3.00%, 2.517 GB&lt;BR /&gt;appstat: 6.00%, 5.034 GB&lt;BR /&gt;hip-reports: 1.00%, 0.839 GB&lt;BR /&gt;traffic: 32.00%, 26.850 GB&lt;BR /&gt;threat: 16.00%, 13.425 GB&lt;BR /&gt;trsum: 7.00%, 5.873 GB&lt;BR /&gt;hourlytrsum: 3.00%, 2.517 GB&lt;BR /&gt;dailytrsum: 1.00%, 0.839 GB&lt;BR /&gt;weeklytrsum: 1.00%, 0.839 GB&lt;BR /&gt;thsum: 2.00%, 1.678 GB&lt;BR /&gt;hourlythsum: 1.00%, 0.839 GB&lt;BR /&gt;dailythsum: 1.00%, 0.839 GB&lt;BR /&gt;weeklythsum: 1.00%, 0.839 GB&lt;BR /&gt;userid: 1.00%, 0.839 GB&lt;BR /&gt;application-pcaps: 1.00%, 0.839 GB&lt;BR /&gt;extpcap: 1.00%, 0.839 GB&lt;BR /&gt;debug-filter-pcaps: 1.00%, 0.839 GB&lt;BR /&gt;dlp-logs: 1.00%, 0.839 GB&lt;BR /&gt;hipmatch: 3.00%, 2.517 GB&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 07:30:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134785#M47392</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-28T07:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134786#M47393</link>
      <description>&lt;P&gt;Hmm, good question. All URL related log files seem to be 'summary' type.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 07:42:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134786#M47393</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-28T07:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134855#M47400</link>
      <description>&lt;P&gt;Generally yes, if you see a drastic decrease in log retention then the only reason would be that you are seeing more traffic and would need to adjust your storage allocation if you want to retain more. That being said it's also probably a good idea to take a look and see if anybody changed/created a rule that is constatntly being logged or if they created something small that logs on start and end. I've run into that issue before where someone enables logging at start and end for testing but forgets to disable it and set the logging to end like we do on everything else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The URL filtering is part of the traffic report quota if memory serves correctly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 14:40:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134855#M47400</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-28T14:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134861#M47403</link>
      <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing two suspected rules with log at start, that is unusual form the rest&amp;nbsp;which only logs at the end.&lt;/P&gt;&lt;P&gt;Now how can I prove that these are the guilty rules?&lt;/P&gt;&lt;P&gt;Are there any way to check how much they are logging? This is so that I can raise a change request for removing the logging at the start.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 15:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134861#M47403</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-28T15:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134864#M47405</link>
      <description>&lt;P&gt;When you look at your traffic logs you can add the 'rule' column&amp;nbsp;which will display the rule that was used and logged the action. As far as logging only at those two logs&amp;nbsp;the best way would be to create a custom report with a rule eq 'whatever' statement to just get the logs for the two rules that you suspect. If it's logging at both start and end you will see many pages of results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind that sometimes there is a legitimate reason that you would want to log at both start and end, but sometimes different admins will accidentally&amp;nbsp;set it to both.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 15:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134864#M47405</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-28T15:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134925#M47413</link>
      <description>&lt;P&gt;One other thing you can check is the 'Max Rows in User Activity Report'. If you hit the maximum number of rows for the report based on 4 days of activity, it won't show any activity further back. &amp;nbsp;If you've changed the activity report to included detailed browsing, increasing the number of rows in the report, this would possibly cause an issue.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 22:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134925#M47413</guid>
      <dc:creator>RFalconer</dc:creator>
      <dc:date>2016-12-28T22:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134932#M47418</link>
      <description>&lt;P&gt;Hi RFalconer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the rows in the report, it was initially set to 50K but we are getting around 2 weeks worth or user activity logs, it was increased to the maximum value and still we are just getting around or less than 4days worth of user activity logs.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 01:28:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134932#M47418</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-29T01:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134944#M47419</link>
      <description>&lt;P&gt;There is a pre-defined report (Reports-&amp;gt;Traffic Reports-&amp;gt;Security Rules) which will show you most used rules. Check if some irrelevant traffic is being logged (DNS, ICMP...) and if some of the most used rules log session start as well.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 06:48:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134944#M47419</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-29T06:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134957#M47422</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53677"&gt;@Ernest_James&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ACC also offers the&amp;nbsp;information on 'Rule Usage' :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rule Usage" style="width: 756px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7047iF85D5579609A25FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2016-12-29_10-14-18.png" alt="Rule Usage" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Rule Usage&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 09:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/134957#M47422</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-12-29T09:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135116#M47457</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53677"&gt;@Ernest_James&lt;/a&gt;&amp;nbsp;Traffic which matches your policy will definitely affect your device. &amp;nbsp;If possible you might want to modify what you log and when as far as URL logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For one function my company uses a 3020 pair and we've got logs back before the 20th. &amp;nbsp;So if you've got a specific requirement it might be worth reallocating storage capacity from one log type to another.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3020_URL Log.JPG" style="width: 496px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7059i812CD7936CABCEC1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3020_URL Log.JPG" alt="3020_URL Log.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3020_Storage.JPG" style="width: 323px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7060i728E7C962F5755A7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3020_Storage.JPG" alt="3020_Storage.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 22:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135116#M47457</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-12-29T22:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135135#M47461</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I do not see rule usage on my ACC, maybe im using a different version.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 01:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135135#M47461</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-30T01:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135137#M47462</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Quotas:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;system: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4.00%, 3.356 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;config: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.00%, 3.356 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;alarm: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.00%, 2.517 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;appstat: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6.00%, 5.034 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;hip-reports: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;traffic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;32.00%, 26.850 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;threat: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;16.00%, 13.425 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;trsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7.00%, 5.873 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;hourlytrsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.00%, 2.517 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dailytrsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;weeklytrsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;thsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.00%, 1.678 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;hourlythsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dailythsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;weeklythsum: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;userid: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;application-pcaps: 1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;extpcap: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;debug-filter-pcaps: 1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dlp-logs: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.00%, 0.839 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;hipmatch: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.00%, 2.517 GB&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 01:42:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135137#M47462</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-30T01:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135140#M47463</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I have checked the Reports&amp;gt;Traffic Reports&amp;gt;Security Rules and found out this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rules.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7061iC40ABC90929337B5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rules.PNG" alt="rules.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Site A&lt;/STRONG&gt; has log problems with 4 days worth of user activity logs, &lt;STRONG&gt;Site B&lt;/STRONG&gt; which has 30G less than &lt;STRONG&gt;SiteA&lt;/STRONG&gt;, can hold up to 3 months of user activity logs.&lt;BR /&gt;&lt;BR /&gt;Please correct me if I am wrong, but Monitor&amp;gt;PDF Reports&amp;gt;User Avtivity Report should be basically text file logs arranged into PDF for better viewing, right? In my opinion, it should not take a lot of space to retain this logs.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 02:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135140#M47463</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2016-12-30T02:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135145#M47464</link>
      <description>&lt;P&gt;Transfered bytes are irrelevant for logging. Log entries are generated per session so look at seesions counter values. A single http download session which transfer 3Gb means one log entry same as a DNS query for this site which transfers only few bytes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the most used rules and see if you log some non relevant sessions like DNS and ICMP or boradcast traffic and similar.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 07:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135145#M47464</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-30T07:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135147#M47466</link>
      <description>&lt;P&gt;Reports are basicaly queries on log files for specific information.&amp;nbsp;So they are sort of an extract of log files. And I believe they are stored seperately from log files so they don't affect log retention directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 07:34:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135147#M47466</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-30T07:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135149#M47468</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53677"&gt;@Ernest_James&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's possible. &amp;nbsp;ACC got a major facelift in PAN-OS 7.0 and some features were added. &amp;nbsp;Possibly pre-7.0 won't have it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It will basically return&amp;nbsp;the same output&amp;nbsp;as seen in the&amp;nbsp;&lt;SPAN&gt;Reports&amp;gt;Traffic Reports&amp;gt;Security Rules. &amp;nbsp;As santonic already pointed out you need to check the number of sessions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 07:52:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135149#M47468</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-12-30T07:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135732#M47541</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked the most used rule but it has been there before. as for the rule with log on start as well seem not to be that used much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2017 11:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135732#M47541</guid>
      <dc:creator>Ernest_James</dc:creator>
      <dc:date>2017-01-04T11:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: PA-3020 log retention period</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135743#M47543</link>
      <description>&lt;P&gt;Even if it's been there always you can optimise it and turn off logging for non interesting traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But to find the source of spike of events: PA FW saves these reports daily. I guess you have to check past reports, find out on which day there was a spike, which rule recorded it and (in the unlikely case you still have logs for that day) you can find out which traffic caused it. If you don't have logs you can check other automated reports and look for possible causes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2017 12:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-3020-log-retention-period/m-p/135743#M47543</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-01-04T12:21:04Z</dc:date>
    </item>
  </channel>
</rss>

