<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic Logs not showing up on Monitoring Tab in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222981#M64106</link>
    <description>&lt;P&gt;Taht should be easy enough to determine, from the CLI execute the command show system logdb-quota&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thsi will show the configured quoteas, then the disk usage and number of days retained - if the traffic usage is at or above the quota and only lists 1-2 days retained, you are using all of the allowed log space.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 18:05:11 GMT</pubDate>
    <dc:creator>JoeAndreini</dc:creator>
    <dc:date>2018-07-19T18:05:11Z</dc:date>
    <item>
      <title>Traffic Logs not showing up on Monitoring Tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222909#M64084</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device Type: PA-220&lt;/P&gt;&lt;P&gt;Software Version: 8.0.11-h1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im having an issue with old traffic logs not showing up on the monitoring tab. I can see live logs but if I want to check the logs for the previous day or previous 2 days then nothing shows up. It only goes back to a certain time. We have cleared all the logs on Friday 13 July so that it can start logging new entries. I logged on today wanting to check the logs for yesterday and I could only go back as far as 14:22. If I filter the time to 14:21 then it shows nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any known issues like this one for the PA-220?&lt;/P&gt;&lt;P&gt;Is there anyone that faced or facing the same issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;Rieyaad&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 11:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222909#M64084</guid>
      <dc:creator>Technical1</dc:creator>
      <dc:date>2018-07-19T11:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs not showing up on Monitoring Tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222974#M64099</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7478"&gt;@Technical1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The 220 doesn't have a lot of logging space allocated. Are you sure that these logs aren't simply getting deleted to allow the current logs to actually write? That's likely what you're running into.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222974#M64099</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-19T17:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs not showing up on Monitoring Tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222981#M64106</link>
      <description>&lt;P&gt;Taht should be easy enough to determine, from the CLI execute the command show system logdb-quota&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thsi will show the configured quoteas, then the disk usage and number of days retained - if the traffic usage is at or above the quota and only lists 1-2 days retained, you are using all of the allowed log space.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:05:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/222981#M64106</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T18:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs not showing up on Monitoring Tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/223062#M64123</link>
      <description>&lt;P&gt;Thanks for the responses. I ran the command and this is the result for the traffic logs:&lt;/P&gt;&lt;P&gt;traffic: 28.00%, 1.260 GB Expiration-period: 0 days&lt;/P&gt;&lt;P&gt;traffic: Logs and Indexes: 1.3G Current Retention: 1 days&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So by looking at that, I can see that the quota for traffic is 1.260GB and the disk usage is 1.3 which is over the quota and the retention is 1 day meaning that it will only show traffic logs for 1 day only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know how I can go about resolving the issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 06:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/223062#M64123</guid>
      <dc:creator>Technical1</dc:creator>
      <dc:date>2018-07-20T06:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs not showing up on Monitoring Tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/223075#M64128</link>
      <description>&lt;P&gt;A few things you migh tlook into:&lt;/P&gt;&lt;P&gt;you could adjust the quotas (Device -&amp;gt; Setup -&amp;gt; Management, click the gear for Logging and Reporting) to add space to the quota for Traffic - you would likely have to remove it from somewhere else.&lt;/P&gt;&lt;P&gt;or&amp;nbsp;investigate exactly what is creating so much traffic that you are filling that log in one day - it may be illegitimate traffic or a misconfigured system.&lt;/P&gt;&lt;P&gt;or, log less - are there any policies that do not need to be logged? maybe somethign that allows ping, etc? (this one may not be possible due to regulatory reasons, of course)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 11:07:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/223075#M64128</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-20T11:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs not showing up on Monitoring Tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/223079#M64130</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7478"&gt;@Technical1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The quota for traffic logs is currently set to 28.00% of your overall disk, which amounts to 1.26 GB of space. The Expiration-period: 0 days simply means that you haven't manually set a expiration date for the logs. Where you see 'current retention' is basically the firewall saying that with the current settings and current log rate it's only able to keep a days worth of traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few of the things that you might not have to log, but may be depending on your enviroment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- DHCP requests&lt;/P&gt;&lt;P&gt;- DNS requests&lt;/P&gt;&lt;P&gt;- ICMP&lt;/P&gt;&lt;P&gt;- SNMP to Print Servers (Printers are extremely talkative)&lt;/P&gt;&lt;P&gt;Essentially you either up the quota assigned to traffic, or you limit the amount of logs that are generated so that you can have a larger retention period and only have the logs for traffic you actually care about.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for how you solve it; well that really depends on what your end game here is. Even if you bump up the quota you won't have enough space on your device to allow anywhere near a weeks worth of logs. So you would either need to trim down what's being logged, or utilize Log Forwarding and push all the logs off of the firewall to something like Panorama or Splunk or similar so that you can analyze the logs off the firewall and aren't limited by its minimal storage capacity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 13:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-not-showing-up-on-monitoring-tab/m-p/223079#M64130</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-20T13:15:32Z</dc:date>
    </item>
  </channel>
</rss>

