Log retention in firewalls and panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Log retention in firewalls and panorama

L1 Bithead

Hi, I have the following question related to log management:

 

  • why PAN-70X0 can't send event logs to Panorama ?
  • are the event logs stored in compressed format ? If so, what is the compression ratio ?

 

Regards

 

Mario

4 REPLIES 4

L5 Sessionator

Hi,

 

For me 70xx plateform are provided with log collector then log are stored in.

You can't forward log directly to Panorama: https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/monitoring/configure-log-forwarding

look for architecture: https://www.paloaltonetworks.com/documentation/70/panorama/panorama_adminguide/manage-log-collection...

 

For me no compression. If you need to estimate disk capacity, look: https://www.paloaltonetworks.com/documentation/60/panorama/panorama_adminguide/set-up-panorama/deter...

 

Hope help.

 

v.

L5 Sessionator

Hi,

 

Just short add. 

For log fowarding to Panorama directly, please look into the V8 release note ....

 

Rgds

 

V.

I was just gonna comment that.  

I noticed in the PAN-OS 8.0 RNs that they support forwarding to Panorama...That being said.  In a production enviornment you'll want to stay away from 8.0 for a while maybe until 8.0.3-5 depending upon how quickly the bugs get mitigated.

Hi Vince,

 

I am reading that logs can be compressed on a PANOS 8.0 firewall. I can find no setting that says compress or gzip logs at all. The guide shows how to do it but when you look in the firewall there is no option to compress.

Not in Device > Log Settings, or Objects > Log Forwarding. I am using a PA-500 although the below article is regarding 7K. This would lead me to believe only the 7K has the capability.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClT3CAK

Line: "Pack and compress more logs on a given send block."

 

thank you,

Nate

  • 2914 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!