<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log forwarding to Panorama from PAN-OS Firewalls for Threats in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297615#M78092</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;&amp;nbsp;Great, thanks for the quick response and noting of the additional licences! We've only initially roled out and not a massive environment, so enabling Pan mode makes sense! Thank you very much!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Nov 2019 09:48:11 GMT</pubDate>
    <dc:creator>mr_almeida</dc:creator>
    <dc:date>2019-11-11T09:48:11Z</dc:date>
    <item>
      <title>Log forwarding to Panorama from PAN-OS Firewalls for Threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297605#M78088</link>
      <description>&lt;P&gt;Hi Gang,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would like to clarify how one sees threat logs from the PAN-OS firewalls in Panorama.&amp;nbsp;&lt;SPAN&gt;Panorama is deployed as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;system mode = management-only&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;VM Mode = VMware ESXi&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Firewalls = PA-3020&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Version = All on 8.1.10&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I have configured &lt;EM&gt;log forwarding&lt;/EM&gt;&amp;nbsp;to Panorama but I never see any threat logs. Log forwarding profile below, it's set on policies of post-rules to perform log forwarding for the configured profile.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22215iDC0AE37CECB00DC7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I check locally on PAN-OS and it does show the firewall is forwarding to Panorama.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could I kindly ask for all your advice on this :)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for reading!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Daniel&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 09:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297605#M78088</guid>
      <dc:creator>mr_almeida</dc:creator>
      <dc:date>2019-11-11T09:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding to Panorama from PAN-OS Firewalls for Threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297612#M78089</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121189"&gt;@mr_almeida&lt;/a&gt;&amp;nbsp;The reason you don't see the logs is, because your Panorama is in "management-only" mode and can only used for manging firewalls, but no log collection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Management Only mode allows the Panorama virtual appliance to operate strictly as a Panorama management server without local log collection capabilities."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/set-up-the-panorama-virtual-appliance-in-management-only-mode.html#id182QC0YK0ED" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/set-up-the-panorama-virtual-appliance-in-management-only-mode.html&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 09:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297612#M78089</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-11-11T09:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding to Panorama from PAN-OS Firewalls for Threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297613#M78090</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply! Yes, I saw this and am wondering if it is ok to change it from management-mode to panorama-mode? System resources aren't an issue so that is fine. I see I would need to attach a secondary disk for logging.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/set-up-the-panorama-virtual-appliance-in-panorama-mode.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/set-up-the-panorama-virtual-appliance-in-panorama-mode.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this advisable or better to go with logging servers and then use collector groups?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 09:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297613#M78090</guid>
      <dc:creator>mr_almeida</dc:creator>
      <dc:date>2019-11-11T09:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding to Panorama from PAN-OS Firewalls for Threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297614#M78091</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121189"&gt;@mr_almeida&lt;/a&gt;&amp;nbsp;If you have all the available resurces the easiest will be to convert to Panorama mode and start collecting logs.&lt;/P&gt;&lt;P&gt;It really depends on the size and design of your deployement. External log collectors can give you redundancy, additional processing power, and log collection close to the log source. However every external log collector will need additional hardware and licenses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 09:45:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297614#M78091</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-11-11T09:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: Log forwarding to Panorama from PAN-OS Firewalls for Threats</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297615#M78092</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;&amp;nbsp;Great, thanks for the quick response and noting of the additional licences! We've only initially roled out and not a massive environment, so enabling Pan mode makes sense! Thank you very much!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 09:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-to-panorama-from-pan-os-firewalls-for-threats/m-p/297615#M78092</guid>
      <dc:creator>mr_almeida</dc:creator>
      <dc:date>2019-11-11T09:48:11Z</dc:date>
    </item>
  </channel>
</rss>

