Log forwarding profile for Correlated Events?

Showing results for 
Search instead for 
Did you mean: 

Log forwarding profile for Correlated Events?

L1 Bithead

Hello all,


It appears that we have had at least a single correlated event in the past seven days, but did not recieve any alert related (via any configured log forwarding profile).


It appears the each match that was correlated did perform a log action, but the actual correlated event did not.


How do I attach a log forwarding action for Correlated Events?







L2 Linker

Did you get anywhere with this?  We're experiencing the same thing.  Thanks.

I got you, fam.



Created By: Solomon Victor (1/10/2017 3:17 PM)

Hope you are doing well.

You may forward the logs for the correlated events by following the below article

Navigate to "Device > Log Setting > Correlation"

Perform the following steps for each log type. For System and Correlation logs, start by clicking the Severity level. For Config and HIP Match logs, start by clicking the Edit icon.

a) Select the Panorama check box if you want to aggregate firewall logs on Panorama. You can then configure Panorama to forward the logs to the external services.

Note: You cannot forward Correlation logs from firewalls to Panorama. Panorama generates Correlation logs based on the firewall logs it receives.

b) Select the SNMP Trap, Email, or Syslog server profile you configured for this log type and click OK.

Configure Log Forwarding: https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/monitoring/configure-log-forwarding

Device Log Settings: https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/device/device-log-settings

Solomon Victor | Technical Support Engineer
Shift Time : 9:00 AM – 5:00 PM PST
Email : svictor@paloaltonetworks.com
Support Contact: US: (866) 898-9087, Outside the US: +1-408-738-7799
Palo Alto Networks | 4401 Great America Parkway, Santa Clara, CA 95054, USA


Would have loved to be in that meeting with the engineers and the UI guys for this one while they tried to figure out where to put this setting.

Panorama > Log Settings > Correlation


Use the Log Settings page to forward the correlation logs to external services.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!