<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA4050/Panorama Log Archive Strategy help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7265#M5382</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is how I have mine setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Device &amp;gt; Log Settings, we have both System and Config logs being sent to the Panorama server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Object &amp;gt; Log Forwarding, we have a profile setup to forward all threat and traffic logs to the Panorama server. We apply this profile under the options of each security policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jan 2011 21:05:30 GMT</pubDate>
    <dc:creator>mharding</dc:creator>
    <dc:date>2011-01-21T21:05:30Z</dc:date>
    <item>
      <title>PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7263#M5380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have one of our new PA4050s running in TAP mode listening to our datacentre firewalls (the firewalls they will replace - these are ASFs running Checkpoint FW1). We are also running Panorama on test machine in our testlab. The PA4050s are logging locally obviously and we're auto archiving off every day the threat, URL &amp;amp; traffic logs to an FTP server in csv format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is - what is the best way forward for implimenting a proper log archiving strategy? I'm coming from a Checkpoint world - where it's fairly easy to archive log files off then load them back onto the management platform to view in the log GUI&amp;nbsp; - and the customer likes this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any way in Panorama of doing this - in fact the size of the logs is worrying also - we're running Panorama on a test client so it's only 10GB disk space for the VMARE - but already it looks as though I'll only get around 2 days of logs on the panorama. Our VAR suggested via PA themselves that we should have around 80GB on our live Panormama (we need the logs for around min 6 months) - but at that rate we would only get about 16 days (ish!!) of logs ever on the Panorama!!&amp;nbsp; The PA4050 itself still has the full weeks worth of logs locally for the time it's been in for - and as mentioned I'm archiving that off - but it still looks very cumbersome to the customer searching through large daily CSV files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help!! Does anyone have any advice?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 15:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7263#M5380</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-01-20T15:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7264#M5381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the same issue.&lt;/P&gt;&lt;P&gt;Hope someone could suggest us something interesting. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 15:47:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7264#M5381</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-01-21T15:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7265#M5382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is how I have mine setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Device &amp;gt; Log Settings, we have both System and Config logs being sent to the Panorama server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Object &amp;gt; Log Forwarding, we have a profile setup to forward all threat and traffic logs to the Panorama server. We apply this profile under the options of each security policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 21:05:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7265#M5382</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2011-01-21T21:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7266#M5383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The logging volumes on the PA-500, PA20xx and PA-40xx are all the same size and are not intended to store excessive amounts of data this is because the primary function they serve is as Firewall's and not reporting devices. Currently if you have a need for greater storage you can use the Panorama product that has a maximum logging volume size of two terabytes or you can use a syslog server to export your logs and then using some other reporting products output the data in a meaningful format.&lt;/P&gt;&lt;P&gt;There is currently no mechanism to import these logs back into the either the PAN-firewall's or the Panorama nor is this feature part of the upcoming 4.0 release. What the 4.0 will provide is a means of mounting an external storage device and utilizing space far exceeding the allocated amounts with the 3.x family.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 21:53:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7266#M5383</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-01-21T21:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7267#M5384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - many thanks to those who replied. I undertood that we wouldn't use the firewalls themselves as long term log storage. We were advised by our VAR that 80GB for long term log data storage on the Panorama would be more than adequate (not sure how they would know this as they didn't have visibility of the data we have going throught our current solution!!). Purchasing more software/hardware (syslog server, reporting software such as splunk) may make our customer baulk though (as would manually trailing through loads of CSV files!!). Thanks for all your input.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jan 2011 13:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7267#M5384</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-01-25T13:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7268#M5385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi pkruse - about the limits on Panorama space. If we run VMARE server on a Windows machine with Panorama installed is the maximum 1TB or 2TB - I've read 2TB is only available if you load VMWARE ESX directly onto the hardware (ie. no host OS underneath).&amp;nbsp; Will the space limit increase you speak of apply to both VMWARE on a windows machine and ESX? Or will the increase in 4.0 only be applied to the ESX variety of install? Is there any news on when 4.0 is scheduled? many thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Feb 2011 13:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7268#M5385</guid>
      <dc:creator>fmd</dc:creator>
      <dc:date>2011-02-09T13:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA4050/Panorama Log Archive Strategy help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7269#M5386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the link that describes the limitations of VMware Server and VMware ESX. In 4.0, you will be able to utilize NFS which will assist in exceeding these disk space limitations. Tentative release date for 4.0 is March of this year.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1393"&gt;https://live.paloaltonetworks.com/docs/DOC-1393&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Renato&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Feb 2011 13:45:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa4050-panorama-log-archive-strategy-help/m-p/7269#M5386</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-02-09T13:45:56Z</dc:date>
    </item>
  </channel>
</rss>

