Log space

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Log space

L3 Networker

Hi - I know there are plenty of discussion about log size - but I don't think anything answers my query.

We installed out Palo Altos (2x 4050s) at the weekend. They sit between our internal datacentres and the rest of the customers network - so they are not internet facing. We log traffic (at start and end) and threat logs (alert on AV/Spy/Vulnerability - no others are enabled) and obviously config and system logs.

We are in active/passive mode (so traffic logs only come from the active PA4050). We forward all logs to Panorama - which is installed in ESX with 1TB of space (we estimated this would give us about 9 months worth of logs). We would then export via the scheduled log export direct from the firewalls a log each day to ensure we kept the logs in some format for the 13months we're required to keep them.

From a logdb-quota on the Panorama we're currently running at around 9.5GB per day of traffic logs alone totalling 34GB since Sunday (threat is only around 70MB - so tiny in comparison).

My thoughts and questions are:

1. Looking at the log quotas on Panorama and the useage of other logs so far - it looks like I could quite happily up the quota for traffic from the 25% (232GB) allocated to 75% allocation - and still leave the other logs OK. Would anyone advise against this?

2. Even if I do that that I would estimate only 74 days or so of logs on Panorama (only two 1/2 months worth - rather than the 9 months we had estimated).,

3. Even if I could keep 9 months on Panorama - the plan was to export CSV from the Palo Alto direct to an FTP server via the scheduled log export so we have them for the 13 months required. Regarding the CSV export - I've increased the max size of the csv file to the max allowed lines of 1048576 - the currently stored logs on the PA4050 itself is 32GB - if I export a this - it will never fit in a single csv file - does it split it into several files? - or does it just bin anything larger than the number of lines? Even if I export only a days worth at 9.5GB - this would also be too large for a single CSV file - how does the PA4050 handle days worth of logs of this size?

4. I've tried a manual test of creating of a CSV file from the traffic logs screen of my passive PA4050 (which has only about 76MB worth in it's database) - the export started - but the link it takes me to on the PA4050 failed:

Firefox can't find the file at https://10.245.57.125/php/monitor/log.export.csv.php?filename=/opt/pancfg/session/pan/csv/7320085078.... Is this due to size or a bug do you think?

Apologies for the long and many tentacled nature of the questions!

Any help most appreciated!

7 REPLIES 7

L3 Networker

Bump - anyone help on this. At the moment we can't alter the logdb settings (at least on the GUI) - we get an error of "management is missing 'storage-partition' " even if we make a tiny change eg. reducing the size of the threat databse to 24% from 25%.

Try the following and let us know if this doesn't resolve your issue.

Go to Panorama Tab -> Storage Partition setup -> Change to NFS Hit OK -> Go back into Storage Partition Setup and switch back to Internal -> Hit OK. Try the commit again.

L0 Member

run this command - set deviceconfig setting management storage-partition internal & commit

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!