Log retention in firewalls and panorama

Reply
Highlighted
L1 Bithead

Log retention in firewalls and panorama

Hi, I have the following question related to log management:

 

  • why PAN-70X0 can't send event logs to Panorama ?
  • are the event logs stored in compressed format ? If so, what is the compression ratio ?

 

Regards

 

Mario

Highlighted
L5 Sessionator

Hi,

 

For me 70xx plateform are provided with log collector then log are stored in.

You can't forward log directly to Panorama: https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/monitoring/configure-log-forwarding

look for architecture: https://www.paloaltonetworks.com/documentation/70/panorama/panorama_adminguide/manage-log-collection...

 

For me no compression. If you need to estimate disk capacity, look: https://www.paloaltonetworks.com/documentation/60/panorama/panorama_adminguide/set-up-panorama/deter...

 

Hope help.

 

v.

Highlighted
L5 Sessionator

Hi,

 

Just short add. 

For log fowarding to Panorama directly, please look into the V8 release note ....

 

Rgds

 

V.

Highlighted
Cyber Elite

I was just gonna comment that.  

I noticed in the PAN-OS 8.0 RNs that they support forwarding to Panorama...That being said.  In a production enviornment you'll want to stay away from 8.0 for a while maybe until 8.0.3-5 depending upon how quickly the bugs get mitigated.

Highlighted
L1 Bithead

Hi Vince,

 

I am reading that logs can be compressed on a PANOS 8.0 firewall. I can find no setting that says compress or gzip logs at all. The guide shows how to do it but when you look in the firewall there is no option to compress.

Not in Device > Log Settings, or Objects > Log Forwarding. I am using a PA-500 although the below article is regarding 7K. This would lead me to believe only the 7K has the capability.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClT3CAK

Line: "Pack and compress more logs on a given send block."

 

thank you,

Nate

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!