Panorama Confusion

Reply
Highlighted
L6 Presenter

Panorama Confusion

I have a PA-3020 V8.1.7 and Panoram V8.18 VM (ESX)

 

I simply require Panorama to both manage the 3020 and collect it's logs.

 

I have tried to follow endless instructions on how to achieve this but now seem to be struggling with different Panorama modes and log collectors...

 

I have added the additional 2T disc as required and although I can manage the firewall via templates I cannot collect any logs from it.

3020 cli   show log-collector preference list ...        Log collector preference list does not exist.

any further advice please...

 

Many thanks in advance.....

 

 

 

L4 Transporter

Re: Panorama Confusion

Hmmm, make sure  you have setup a log forwarding profile on the FWs to PUSH the logs to the Panorama.

 

I did not see that you had done this yet.

 

 

Help the community: Like helpful comments and mark solutions
L4 Transporter

Re: Panorama Confusion

run this command on the FW

 

show logging status 

 

on the PAnorama run this command 

 

show logging-status device serial no?

 

try restarting the log receiver on fw

 

debug software restart process log-receiver

L6 Presenter

Re: Panorama Confusion

Thanks for your replys

 

@SteveCantwell  yes, good point but i do have a log forward profile configured. not sure if it's working but it's there...

 

@MP18  as below.  I think my issue is with Panorama. do you run a similar setup.  if so.. do you have a local log collector configured on Panorama VM.   the instructions say that after I have added another 2TB and restart panorama it will auto add a local log collector but this is not happening.

 

I will post this instruction when i find it again.

L6 Presenter

Re: Panorama Confusion

showlogfw.pngshowlogpanorama.png

L6 Presenter

Re: Panorama Confusion

this is what should happen..

 

Return to the Panorama CLI and run the following command.

> request system system-mode panorama
Enter y when prompted to continue. After rebooting, Panorama automatically creates a local Log Collector (named Panorama) and creates a Collector Group (named default) to contain it. Panorama also configures the virtual logging disk you added and divides it into separate 2TB disks. Wait for the process to finish and for Panorama to reboot (around five minutes) before continuing.
 
 
 
but the log collector is not created, i can add manually but still no logging.
L6 Presenter

Re: Panorama Confusion

also...

this is the output from Panorama disk details.

i would have thought that the 2TB logging disk should be seperate.

 

admin@Panorama> show system disk details

 

 Name   : sdb

State  : Present

Size   : 2097152 MB

Status : Available

Reason : Admin enabled

 

 

admin@Panorama>

L6 Presenter

Re: Panorama Confusion

cancel previous on what should happen, i am now doing a new install via this documentation.

 

https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/set-up-panorama/set-up-the-panorama-vi...

 

but could someone confirm if i still need to use a local log collector.

L6 Presenter

Re: Panorama Confusion

ok getting better...  so will need to re visit this on Monday.   thanks all for your help.

 

ashow2.png

L4 Transporter

Re: Panorama Confusion

Yes you will need local log collector --default ----if you do not have any external log collector like M500

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!