logdb export very slow then fails

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

logdb export very slow then fails

L1 Bithead

Hi,

I have a PA-500 which is running PAN-OS 5.0.9 and a Panorama server running PAN-OS 5.1. The Panorama is new and I would like to get all the historic traffic logs from the 500 to the Panorama. I have used scp export logdb user@server:logdb to export the logdb off the 500. To begin with the ssh sessions were timing out before the file had finished so I set keep alives to try to get round this issue.

The export ran for about two days and it had appeared to finish. When I try to import the log it gets as far as ./hipmatch/.scheme.500.hipmatch.4.0.5 and stops (see screen shot).

Import-error-2.png

All that happens after this is that the traffic log on the Panorama is empty and it wont accept any new logs from the 500. It's almost like the logdb is corrupt. The exported file was only about 26GB and the settings on the 500 says the logs are set to be 118GB

It seems as if the log export is very slow it only hits about 5mbps at its peak, its connected to gigabit infrastructure.

Has anyone else had a similar issue or know another way to get the logs into the Panorama?

Thanks,

Gareth

8 REPLIES 8

L7 Applicator

Hello Gareth,

Have you tried exporting logs through TFTP export..? Just to check if, through TFTP log-export is working or not.

Thanks

Hi Hulk,

Thanks for the suggestion, however there doesn't seem to be a corresponding import command for the Panorama.

Gareth

Hello Gareth,

SCP option only works for linux/unix servers. Are you trying to export from PAN firewall to directly Panorama (5.1.x).?


Related article: CLI Commands to Export/Import Configuration and Log Files


Thanks

Hi Hulk,

I'm exporting from the 500 to a Linux server then importing from the server to the Panorama.

Thanks,

Gareth

Ok, then it should work smoothly. Is there any intermediate device, which can cause a problem here..?

Thanks

Traffic between the 500 & panorama and the server does have to pass through a firewall. The ports are open but I guess it could be tearing down the session as its been open for such a long time? I'll try putting a server in the same subnet and see if that makes a difference.

The default tcp timer is 30 minutes.  You could create a custom service on the firewall with a longer timeout value if you think the session keep alive is not working.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Unfortunately the answer to my question is you cant import the traffic logs from a PA to a Panorama.

Thanks for everyone suggestions.

  • 3389 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!