After software upgrade firewall stopped to sending syslog

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

After software upgrade firewall stopped to sending syslog

L2 Linker

We upgraded PA-1410 from sofware release 11.0.2.-5 to 11.1.6-h3. The upgrade itself went well, but a few days later firewall stopped to send syslog messages. Executed tcpdump on the management port, but there is no syslog traffic at all. Checked the system resources, logrcvr servcie seems to be running. I tried to restart the service, and realize that, after restart two syslog session appeared in the traffic log, but nothig more. After a while, resatarted the service again, and the same happend, two syslog messages and nothing further.

Did anyone face this isse?

 

Regards,

Mihaly

6 REPLIES 6

Cyber Elite
Cyber Elite

@mkukucska Never face this issue on PA 1410 running PAN OS 11.1.4-h7.

This is the preferred version.

MP

Help the community: Like helpful comments and mark solutions.

@MP18 What do you mean? Based on the doc we are using for choose preferred release, 11.1.6-h3 is the preferred release since 02/27/25.

https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-...

 

@mkukucska Seems 11.1.4-h7 is past preferred release now. You are on Right PAN OS.

Please check this link for Troubleshooting.

How To Troubleshoot Connection Failures To Syslog Servers in PA... - Knowledge Base - Palo Alto Netw...

 

Regards 

MP

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

@mkukucska,

You might want to look at PAN-272849 and see if you're impacted by that potentially. You would need to apply 11.1.8 to actually get the fix since you wouldn't be able to apply 11.1.7 on a 1410. Personally I've kept most people off of 11.1 for the time being unless they can thoroughly validate things in a lab environment; I've seen people have better success staying with 10.2 for the time being or actually moving forward to 11.2.

 

https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-7-known-and-addressed...

@BPry Our case different, TCP syslog server stopped, even though server is reachable via icpm echo. 

@MP18 Already checked it, but this article is for versions below 11.1

 

Regards,

Mihaly

  • 464 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!