<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama is dropping lot of traffic to  syslog splunk in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392494#M90904</link>
    <description>&lt;P&gt;I had to give you a like for the Linux client&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt;, because you're right ; - )&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 21 Mar 2021 02:44:11 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-03-21T02:44:11Z</dc:date>
    <item>
      <title>Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387354#M90360</link>
      <description>&lt;P&gt;I have a active-standby panorama cluster version 8.1.17 that manages about 40 firewalls.&amp;nbsp; The active-cluster panorama is also a log collector-group.&lt;/P&gt;&lt;P&gt;20 firewalls send traffic/threat/URL logs to active panorama and the other 20 firewalls send traffic/threat/URL logs to the standby panorama.&amp;nbsp; From there, I configure panorama to forward these logs to syslog splunk.&amp;nbsp; I have PAN TAC support look at the configuration and they confirm the setup is good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the issue.&amp;nbsp; When I use the command "less mp-log syslog-ng.log", I can see the drop increment from panorama to the syslog splunk every 30 minutes or so.&amp;nbsp; The counter is measured every ten minutes.&amp;nbsp; On the syslog Splunk side, they confirmed that the traffic never arrived in tcpdump (syslog is clear text so we can decode the missing logs).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've opened a ticket with PAN support and waiting to hear back from them but it is currently with the first tier level TAC support so not much hope so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why would panorama stop forwarding log to external syslog splunk?&amp;nbsp; Has anyone seen this issue before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 13:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387354#M90360</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-02-23T13:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387366#M90362</link>
      <description>&lt;P&gt;have you tracked global counters and log forwarder statistics? maybe the log rate is too high for it to be able to complete each forward&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 14:09:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387366#M90362</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-23T14:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387412#M90368</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;:&amp;nbsp; What is the command do you recommend?&amp;nbsp; I am using "&lt;SPAN&gt;debug log-collector log-collection-stats show log-forwarding-stats | match syslog&lt;/SPAN&gt;" and I am seeing this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;syslog enqueued count: 3260998077&lt;BR /&gt;syslog sent count: 3260769863&lt;BR /&gt;syslog dropped count: 422974378&lt;BR /&gt;syslog Queue depth: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What do you mean by the log rate is too high?&amp;nbsp; My panorama is running in AWS with the biggest available EC2 available.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 16:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387412#M90368</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-02-23T16:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387474#M90375</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So just because you deploy an ever bigger instance doesn't mean it'll handle the amount of logs being generated. You pretty quickly run into an area of diminishing/no return on additional resources.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 20:56:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387474#M90375</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-23T20:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387498#M90384</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;:&amp;nbsp; My instance is 16CPU with 64GB RAM.&amp;nbsp; According to PAN, it is capable of handling of 10,000 logs/sec.&amp;nbsp; Maximum logs/sec in my situation is around 4,500 logs/sec so I have plenty of resource on the Panorama to handle the log.&amp;nbsp; Waiting for the next move from TAC support.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 00:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387498#M90384</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-02-24T00:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387708#M90411</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please keep us posted what TAC says about this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 03:52:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/387708#M90411</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-02-25T03:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392038#M90841</link>
      <description>&lt;P&gt;Just a quick update on this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It turned out that my log collectors spiked to 15K/sec for incoming log and the instance we have is only for 10K/sec for incoming logs.&amp;nbsp; I am going to increase the size, CPU and memory, of the AWS EC2 instance.&amp;nbsp; Hopefully, it will go away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 13:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392038#M90841</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-03-18T13:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392053#M90844</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I am curios how did you find the spikes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 14:02:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392053#M90844</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-03-18T14:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392439#M90895</link>
      <description>&lt;P&gt;I use a python to log into Panorama every 5 seconds and run these three commands and pipe them into an ascii file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show clock | match GMT&lt;/P&gt;&lt;P&gt;Sat Mar 20 07:40:04 GMT 2021&lt;BR /&gt;&amp;gt; debug log-collector log-collection-stats show log-forwarding-stats | match "syslog dropped count"&lt;BR /&gt;syslog dropped count: 23026208&lt;BR /&gt;&amp;gt; debug log-collector log-collection-stats show incoming-logs | match "Incoming"&lt;BR /&gt;Incoming log rate = 1389.45&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I use grep and awk to find out if the count the diff in the dropped count and Incoming log rate base on the timestamp.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN TAC support also has something similar but they run it in Teraterm for Windows.&amp;nbsp; Real engineers use Linux &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 07:46:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392439#M90895</guid>
      <dc:creator>dtran</dc:creator>
      <dc:date>2021-03-20T07:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama is dropping lot of traffic to  syslog splunk</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392494#M90904</link>
      <description>&lt;P&gt;I had to give you a like for the Linux client&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41973"&gt;@dtran&lt;/a&gt;, because you're right ; - )&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Mar 2021 02:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-is-dropping-lot-of-traffic-to-syslog-splunk/m-p/392494#M90904</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-03-21T02:44:11Z</dc:date>
    </item>
  </channel>
</rss>

