Panorama uses 33% of log disk space for logd database for downgrade compatibility.
If you don't have plan to downgrade to pre-8.0 it is wasted space.
There is feature request 10931 to get rid of it.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5aCAC
@Raido wrote:Panorama uses 33% of log disk space for logd database for downgrade compatibility.
If you don't have plan to downgrade to pre-8.0 it is wasted space.
There is feature request 10931 to get rid of it.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5aCAC
An in addition to waste of space, the retention values reported in the WebUI and by SNMP show the logs from logd - the old format and unfortunately this value normally much higher than the logs that you really have access to in elastic search.
FR ID 10931 (Use logd disk space for elastic search in Panorama) is added to the list.
Thanks @Raido
Added FR ID 4788 and 6609 to the list.
FR ID 4788: Block emails based on domains in "to", "cc" or "bcc", also log these in addition to only "to" and reply with smtp 541 when blocked
FR ID 6609: Add "Threat Email" to email subject when something malicious was detected and also log "cc" and "bcc"
Feature Request ID is 12264
Report based on HIP match failure, specifically what items failed HIPS
@michaelfriedmanAdded FR ID 12264 to the list. Thanks for sharing
Added FR ID 12783: Log E-Mail links forwarded to Wildfire
Update on FR ID 10173 (Automatically open browser when Global Protects a Captive Portal and opens a configurable website): This feature request was implemented in Global Protect 5.0.4 starting with content update 8181.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!