Where are the administrator access logs on Panorama?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Where are the administrator access logs on Panorama?

L2 Linker

In Panorama where are the adminsitrator access logs? I.e. if I want to see when a adminsitrator user last accessed the system.  I know where that is on the PA firewalls, but on Panorama??

1 accepted solution

Accepted Solutions

L2 Linker

Found it in case anybody else ever runs into this.  The "Device Grouping" view also changes the left hand menu as well, I didn't realize it was contextual; only though the information displayed on the side was device grouping dependent.

 

So in my case I needed "All" because Panorama itself isn't a device which can be grouped

View solution in original post

11 REPLIES 11

Cyber Elite
Cyber Elite

You don't see it in system log?

 

panorama-admin-login.PNG

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

did you enable system log forwarding ?

system log forwarding.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Raido: LOL I don' t even have that option on my Panorama system (though I do on my PA's):

 

Capture.PNG

reaper: Yes though I assume it still keeps local logs (as I don' t have access to where the logs are actually forwarded to; don't ask, org politics)

Hi @PeterT then it would appear your admin account does not have access to these logs (physically or through the GUI)

 

your only recourse will be to use the context switch to look at the local logs on the firewall

 

 

 

Quis custodiet ipsos custodes 😉

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper That makes no sense given I'm logged on as the "superuser" on the Panorama 🙂 .. i.e. have rights to everything, I just don't have rights to the Arcsight SIEM where the remote logs are dumped 😉 .  I should still be able to see the panorama local access logs though IMHO as would be a wierd situation where the panorama superuser could see the logs on the FW's (which I can) but not panorama itself

well that's awkward 😛

 

ehm, what version of PAN-OS are you running? those log files should be there... can you try checking the CLI ?

 

> show log config direction equal backward
> show log system direction equal backward
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Panorama 8.0.2

 

Both work via CLI, the question then (per screenshot above) where is it via the Web UI?  I'm thinking possibly bug / call support on this one now lol.

yeah... if you're superuser those logs should be visible...

one last thing you could try (before calling support) is to 'reset' the gui : https://<panorama IP>/debug

 

once logged in, click the 'clear preferences' button, this will clear your admin's gui config, in case some flag got set

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

As a superuser (admin) I also don't see System under logs in Panorama. Running 7.1.9 here. The admin user has it on the NGFWs, just not Panorama.

L2 Linker

Found it in case anybody else ever runs into this.  The "Device Grouping" view also changes the left hand menu as well, I didn't realize it was contextual; only though the information displayed on the side was device grouping dependent.

 

So in my case I needed "All" because Panorama itself isn't a device which can be grouped

  • 1 accepted solution
  • 5901 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!