collector group with redundancy not working properly

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

collector group with redundancy not working properly

L3 Networker

we have configured Panorama M200 in HA , configured managed collector with local log collector , configured collector group and added local log collector of both panorama,  redundancy is enabled in collector group (log forwarding preference is not configured.

 

Above configuration we have done to store same logs on both local log collector and enable redundancy So if complete Pri M200 box failed , we will have same logs in Sec M200 local log collector.

But as per configuration logging is not happening properly on secondary panorama , there is a difference in system dis-space utilization

Deepak25_0-1623763316613.png

Also we sec panorama log collector not receiving any log ( as per our requirement and redundancy conifg secondaryM200 also should store the logs)

Deepak25_1-1623763766133.png

 

is there any configuration issue , or the output in sec m200 is normal ? how we can check same logs are store or not in sec M200 ?

 

We are able to see same logs in both M200 webgui , as per my understanding its because of collector group config .

8 REPLIES 8

@Deepak25 

 

We have check mark Enable log redundancy across collectors.

And Firewall is added to M200.

 

From FW  CLI

 

show log-collector preference-list

Log Collector Preference List
Forward to all: No
Serial Number: 007307001xxx IP Address: 10.7.2.104 IPV6 Address: unknown
Serial Number: 007307001xxx IP Address: 10.7.2.103 IPV6 Address: unknown

 

fw send logs to Primary M200 and if it is down then it will send to another one.

 

Regards

 

MP

Thanks for sharing the setting.

We have same setting only log forwarding preference list not configured as we want to forward logs to both local log collector.

I think theoretically , If redundancy is enabled no point of creating log forwarding preference list as logs getting stored in both managed collectors.

Please correct me if I am wrong.

@Deepak25 

 

you need preference list as if one log collector dies then firewall will not send logs to another collector in preference list.

Also you will get system alert emails that fw has lost connection to log collector.

 

Regards

MP

@Deepak25 

 

Also you can see logs on secondary Panorama by show log traffic command from CLI.

 

Regards

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!