- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-01-2026 06:49 PM
When setting the password complexity on the Palo Alto firewall, I set only the expiration date to 60 days and locked the account. Is there a way to keep or leave related logs in the system log before the expiration date? If there is any content, please also provide a link to a site where I can refer to it.
09-02-2026 04:40 PM
Hi @e.Lee984645 ,
If you are using a local administrator account, you can configure an Expiration Warning Period in addition to the Required Password Change Period.
For example, under Device > Setup > Management > Minimum Password Complexity, you can configure:
When the administrator logs in during the configured warning period, PAN-OS will prompt them that the password is approaching expiration and should be changed.
Based on the documented behavior, this warning is presented to the administrator during login rather than being generated as a specific System log event prior to expiration. System/authentication logs can indicate the condition after the password has expired or the account has been locked because of expiration.
You can also configure these values through a Password Profile under Device > Password Profiles if you want the settings applied to specific administrator accounts.
Hope this helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

