<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log-Collector Issue with 10.x to 10.x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/log-collector-issue-with-10-x-to-10-x/m-p/412884#M92892</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a strange situation, maybe someone can help:&lt;/P&gt;&lt;P&gt;Panorama on 10.0.6, Firewalls mostly on 9.1.x.&lt;/P&gt;&lt;P&gt;We onboarded the 1st 10.0.5/6 firewalls and noticed, that we don't receive any logs within our dedicated log collector.&lt;/P&gt;&lt;P&gt;The collector group is configured to receive logs from the new onboarded firewalls.&lt;/P&gt;&lt;P&gt;When looking in detail at ms.log and logging-service.log, I see SSL-Errors:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chacko42_0-1623654697519.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34384iB01B1B280E1B305C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Chacko42_0-1623654697519.png" alt="Chacko42_0-1623654697519.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;We use the pre-defined certificates for panorama communication, but obviously, sth. changed with 10.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jun 2021 07:12:31 GMT</pubDate>
    <dc:creator>Chacko42</dc:creator>
    <dc:date>2021-06-14T07:12:31Z</dc:date>
    <item>
      <title>Log-Collector Issue with 10.x to 10.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-collector-issue-with-10-x-to-10-x/m-p/412884#M92892</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a strange situation, maybe someone can help:&lt;/P&gt;&lt;P&gt;Panorama on 10.0.6, Firewalls mostly on 9.1.x.&lt;/P&gt;&lt;P&gt;We onboarded the 1st 10.0.5/6 firewalls and noticed, that we don't receive any logs within our dedicated log collector.&lt;/P&gt;&lt;P&gt;The collector group is configured to receive logs from the new onboarded firewalls.&lt;/P&gt;&lt;P&gt;When looking in detail at ms.log and logging-service.log, I see SSL-Errors:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chacko42_0-1623654697519.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34384iB01B1B280E1B305C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Chacko42_0-1623654697519.png" alt="Chacko42_0-1623654697519.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;We use the pre-defined certificates for panorama communication, but obviously, sth. changed with 10.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 07:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-collector-issue-with-10-x-to-10-x/m-p/412884#M92892</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2021-06-14T07:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Log-Collector Issue with 10.x to 10.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/log-collector-issue-with-10-x-to-10-x/m-p/414869#M93192</link>
      <description>&lt;P&gt;did you commit the newly onboarded config to 1) panorama 2) the collectors 3) the firewalls&lt;/P&gt;&lt;P&gt;in the commit dialog you can select 'edit selection' and then in the collectors tab, there you may need to check the box before the config is pushed to the collectors so they start accepting logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the firewall, check if it's aware it should be sending to a collector:&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN class="s1"&gt;show log-collector preference-list&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;gt; request log-collector-forwarding status&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 21:43:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/log-collector-issue-with-10-x-to-10-x/m-p/414869#M93192</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-06-23T21:43:12Z</dc:date>
    </item>
  </channel>
</rss>

