<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuration of Logs PA220  - log database exceeds alarm in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-logs-pa220-log-database-exceeds-alarm/m-p/186457#M56878</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just can't get a handle on logging. Currently the PA220 reports with PanOS 8.0.5 "Current size (357 MB) of threat log database exceeds alarm threashold value (90%) of total allowed size (368MB").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already tried to change the quota % values under Device -&amp;gt; Management -&amp;gt; Logging and Reporting Settings. But how do I get the PA to say that if 90% logs have been reached, then delete the oldes one? I don't want the file system to fill up and the PA to stop running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be yours best practices?&lt;/P&gt;&lt;P&gt;I also move the logs traffic, threat, url, data, and logs by Sheduled Log Export&amp;nbsp;Job via FTP every day. Are these all Logs or what is database logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My device is only around 10days active and then the space of logs full? Very sad.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2017 14:43:48 GMT</pubDate>
    <dc:creator>clonesheep</dc:creator>
    <dc:date>2017-11-10T14:43:48Z</dc:date>
    <item>
      <title>Configuration of Logs PA220  - log database exceeds alarm</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-logs-pa220-log-database-exceeds-alarm/m-p/186457#M56878</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just can't get a handle on logging. Currently the PA220 reports with PanOS 8.0.5 "Current size (357 MB) of threat log database exceeds alarm threashold value (90%) of total allowed size (368MB").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already tried to change the quota % values under Device -&amp;gt; Management -&amp;gt; Logging and Reporting Settings. But how do I get the PA to say that if 90% logs have been reached, then delete the oldes one? I don't want the file system to fill up and the PA to stop running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be yours best practices?&lt;/P&gt;&lt;P&gt;I also move the logs traffic, threat, url, data, and logs by Sheduled Log Export&amp;nbsp;Job via FTP every day. Are these all Logs or what is database logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My device is only around 10days active and then the space of logs full? Very sad.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 14:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-logs-pa220-log-database-exceeds-alarm/m-p/186457#M56878</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2017-11-10T14:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration of Logs PA220  - log database exceeds alarm</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-logs-pa220-log-database-exceeds-alarm/m-p/186466#M56879</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43193"&gt;@clonesheep&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The firewall automatically deletes logs that exceed the expiration period if you've set one. Once your storage quota for that log has been reached the firewall will automatically delete older logs to create space, regardless of expiration period.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;EM&gt;only&lt;/EM&gt; time that this should ever&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; be true, is if you've enabled the 'Stop Traffic when LogDb Full' feature under the Logging and Reporting Settings on the device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA220 does not have a lot of storage, by the very nature of the device. Total you have 32GB to share for logging, the actual OS, software updates, and all that other good stuff. Look at setting up Log Forwarding on the device and put these logs in a location that you maintain without the need for an FTP job. It also is probably worth looking at what you are actually logging, do you actually care to maintain all of this informaiton.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the amount of logs that get generated it isn't shocking to here that a 220 is only capable of handling 10 days of logs; if you actually care about logging and need to keep over 368MBs of logs you'll need to setup Log Forwarding and offload these logs to another location. The 220 is a very capable device, but it certaintly doesn't have a large amount of storage.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 15:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-logs-pa220-log-database-exceeds-alarm/m-p/186466#M56879</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-10T15:21:59Z</dc:date>
    </item>
  </channel>
</rss>

