- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-02-2020 04:58 PM
Hey everybody,
I'm setting up a 7050 with a log forwarding card to a dedicated log collector. On the log collector, I have it set to device log collection and collector group communication on ethernet1/5. I have log settings configured as well as a log forwarding profile. With traffic running through the firewall, I'm seeing hits against rules on the 7050, but when I run "show logging-status device <SERIAL>" I see the destination IP of ethernet1/5, and I'm seeing logs received for system and config, but I'm not getting any traffic logs. In the panorama manager, I can see the system and config logs, but I'm not seeing any traffic logs. Any ideas what could be the issue?
12-02-2020 05:29 PM
Can you take a look at this article to see if it helps?
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClT3CAK
12-02-2020 07:33 PM
Thanks for the suggestion. In PAN-OS 9.0 I don't have an option to turn on high speed log forwarding. I did enable send to all collectors in the preference list, but that didn't seem to change anything.
02-08-2021 12:23 PM
It turned out to be an issue with the optics being used in the log forwarding port. Once we used a supported optic, everything worked as expected.
02-09-2021 12:14 AM
The Log Forwarding Card (LFC) is a high-performance log card that forwards all dataplane logs (traffic and threat for example) from the firewall to one or more external logging systems, such as Panorama or a syslog server. Because the dataplane logs are no longer available on the local firewall, the ACCtab is removed from the management web interface and Monitor > Logscontain only management logs (Configuration, System, and Alarms).
There is one LFC model used for both the PA-7050 and PA-7080 firewalls. On the PA-7050 firewall, you must install the LFC in slot 8 and on the PA-7080 firewall you must install the LFC in slot 7.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!