After upgrade Panorama from 8 to 9 Panorama stopped sending GP-logs to Qradar syslog server.

cancel
Showing results for 
Search instead for 
Did you mean: 

After upgrade Panorama from 8 to 9 Panorama stopped sending GP-logs to Qradar syslog server.

L0 Member

Before the upgrade everything was working just fine, now after upgrade still I can see the GP-logs sent from the Firewalls to Panorama, but Panorama still unable to sent those logs to Qradar syslog server. Connectivity between the 2 devices is good.

I found the below document to review the configuration to see if anything is missing but the document is for PAN-OS 6.0, 6.1, 7.0 and that is too old. After a lot of research I have been not able to find a document just like this one but for version 8-9 or 10 but without any luck.

HOW TO FORWARD FIREWALL LOGS FROM PANORAMA THROUGH SYSLOG2

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEVCA0

 

If any one can shed some light regarding this matter will be highly appreciated!!.

 

 

 

1 REPLY 1

Cyber Elite
Cyber Elite

The document you referenced may be old, yet the configuration is the same.

 

Now, my question for you is more about the upgrade from 8 to 9.

In 8.0, it is a possibility that your Panorama was in Legacy Mode (mgmt and logging combined)

In your upgrade to 9.0, perhaps, not sure, that your Panorama is now only in mgmt mode, and that is why it is not forwarding your logs.

Look at your dashboard and confirm what the system-mode is.

 

for mine.. I needed to upgrade CPU and memory for my 9.x upgrade to create a panorama mode vs (mgmt-only, log-collector modes)

Now you may still have legacy mode, but it is the first place you should look.

 

UPDATE:   If it is ONLY the GP logs, then my mistake.

It could be in the log collector group area where you see all of the types of logs

 

SteveCantwell_0-1613566574707.png

 

but you need to confirm you have scrolled all the way to the left to choose GP logs (if I am understanding your issue)

 

 
 

 

 

 

 

Help the community: Like helpful comments and mark solutions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!