<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log forwarding to Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222334#M63947</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55509"&gt;@aespinosa&lt;/a&gt;&lt;/P&gt;&lt;P&gt;If there is somewhere another firewall between the one mentionned in your post and your panorama, there might be another (ugly/bad/not recommended) solution. Depending on the actual amount of logs you could then only allow the connection between the firewall and panorama off business hours. As mentionned this only works if there is enough disk space to store the logs of the day. And this "solution" also means that you cannot manage the firewall from panorama during the day. And you will also loose the logs of one day completely if the firewall dies. So as I said its ugly to do it like that but this the logs are only forwarded outside business hours...&lt;/P&gt;</description>
    <pubDate>Sun, 15 Jul 2018 12:04:40 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-07-15T12:04:40Z</dc:date>
    <item>
      <title>Log forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222134#M63895</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have some problems with log forwarding from firewall to Panorama because it is consuming a lot of bandwidth. I have configured the firewall to buffer the logs before foward them to Panorama. I would like to know the following:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* When log forwarding initiates from firewall to Panorama (50% or 90% of buffered size for example)?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* How I control the log forwarding to schedule it during off business hours?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyone can help me?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 07:16:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222134#M63895</guid>
      <dc:creator>aespinosa</dc:creator>
      <dc:date>2018-07-13T07:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222219#M63917</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55509"&gt;@aespinosa&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Log buffering is only intended for overcoming connectivity issues with panorama: if the firewall is in a location where connectivity to panorama can be spotty ?(due to ISP peering, remote location, bandwidth,...) enabling the buffer ensures no logs get lost when the connection to panorama is lost: the firewall temporarily writes to disk while connectivity is restored and then resumes from the last log in it's buffer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this works in 30 second increments&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-log-collection/modify-log-forwarding-and-buffering-defaults" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-log-collection/modify-log-forwarding-and-buffering-defaults&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can try enabling &lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-Log-Suppression-Works/tac-p/185987#M945" target="_blank"&gt;log-suppression&lt;/A&gt; to reduce repetitive logs, bit&amp;nbsp;to truly reduce bandwidth usage, you will need to dial down which logs are forwarded&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 14:03:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222219#M63917</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-13T14:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222334#M63947</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55509"&gt;@aespinosa&lt;/a&gt;&lt;/P&gt;&lt;P&gt;If there is somewhere another firewall between the one mentionned in your post and your panorama, there might be another (ugly/bad/not recommended) solution. Depending on the actual amount of logs you could then only allow the connection between the firewall and panorama off business hours. As mentionned this only works if there is enough disk space to store the logs of the day. And this "solution" also means that you cannot manage the firewall from panorama during the day. And you will also loose the logs of one day completely if the firewall dies. So as I said its ugly to do it like that but this the logs are only forwarded outside business hours...&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2018 12:04:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama/m-p/222334#M63947</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-15T12:04:40Z</dc:date>
    </item>
  </channel>
</rss>

