Log Retention Period Issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Log Retention Period Issue

L0 Member

How do i can able to increas the log retentuion period on Palo Alto?

it haven't got modified even it have changed in GUI

1 REPLY 1

Community Team Member

Hi @naniknown ,

 

In PAN-OS, you cannot explicitly set a retention period (like "90 days") for local logs. Instead, you modify Max Days (an expiration ceiling) or Log Storage Quotas (the percentage of the hard drive allocated to that log type).

 

If your retention period isn't increasing even after making changes in the GUI, it almost always means your firewall is generating logs faster than your allocated disk quota can handle. Once the database partition hits its max storage capacity, the firewall automatically overwrites the oldest logs to make room for new ones, regardless of your "Max Days" setting.

 

Here are some things you can try:

 

  • Tweak your Quotas in the GUI:

    If you have log types you don't care much about (like overly verbose URL filtering or decryption logs), you can steal space from them and allocate it to your Traffic or Threat logs.

    • Go to Device > Setup > Management.
    • Click the gear icon next to Logging and Reporting Settings.
    • Under the Log Storage tab, increase the percentage for the logs you want to keep longer.
    • Note: Ensure your "Unallocated Space" remains at or above 9% for performance efficiency, and don't forget to Commit the changes!

  • Consider External Logging (The Long-Term Fix)

    Hardware firewalls have fixed local storage limits. If you are maxing out your disk quota and still only getting a few days of data, your hardware simply cannot hold more. To get true long-term log retention, you will need to forward your logs to an external destination:
    • Panorama / Dedicated Log Collector
    • Strata Logging Service (Cloud)
    • External Syslog / SIEM Server

Hope this clarifies things,

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 48 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!