<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different log retention periods in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303576#M79015</link>
    <description>&lt;P&gt;is syslog an option here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;some basic grep stuff will pick out required lines and logrotate for archive of specific&amp;nbsp; files.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Dec 2019 10:49:34 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-12-13T10:49:34Z</dc:date>
    <item>
      <title>Different log retention periods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303567#M79014</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for privacy reasons our customer has different log retention periods. He want's to delete all &lt;SPAN&gt;personally identifiable traffic log for traffic from internal to external to delete after 7 days. Also traffic logs for blocked traffic from externel to internal should be deleted after 7 days. Traffic logs for allowed traffic from externel should never (until disk full) been deleted. Internal server traffic logs should be deleted after 30 days.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any idea, how to resolve this? Panorama doesn't exist. Splunk isn't an option, because there are 20GB of log volume per day.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Robert&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 10:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303567#M79014</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-12-13T10:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Different log retention periods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303576#M79015</link>
      <description>&lt;P&gt;is syslog an option here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;some basic grep stuff will pick out required lines and logrotate for archive of specific&amp;nbsp; files.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 10:49:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303576#M79015</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-13T10:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Different log retention periods</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303725#M79040</link>
      <description>&lt;P&gt;@Retired Member,&lt;/P&gt;&lt;P&gt;When you start wanting to split how logs are retained your going to have to get them off the box to be processed elsewhere. For what you are asking I would personally setup a Graylog installation and then make sure that all of the required logs are forwarded to the Graylog instance and set a minimal retention on the firewall itself. You can then easily configure these requirements within Graylog to meet your requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Graylog is an open-source and doesn't require that you purchase the Enterprise solution. The open-source solution doesn't have any limitations, but the Enterprise solution is priced on ingest&amp;nbsp;just like Splunk.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 22:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-log-retention-periods/m-p/303725#M79040</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-13T22:40:42Z</dc:date>
    </item>
  </channel>
</rss>

