MGMNT Slow and Serching logs slow and Syslog server issue.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

MGMNT Slow and Serching logs slow and Syslog server issue.

L4 Transporter

Device Model: PA-5220 HA Mode Active-standby

PAN-OS 10.0.0

The questions below as I couldn't find anything on Palo Alto website.

 

Recently we have upgraded Palo Alto to v10.0.0.

 

1. Web management interface became very slow and searching logs takes very long time to load.

Kindly advise if there’s any solution for that. Can we disable services of some added unused features, like SDWAN or IoT? Or is there any work-around to make it faster?

 

2. Integration with ArcSight Syslog server is not working well as logs are not parsed correctly.

Seems the raw data format sent from Palo Alto changed in this version. Kindly advise how to fix this.

Can we change the format to be similar to 9.0.x or 9.1.x format?

26 REPLIES 26

L1 Bithead

I was reading the 10.1.5 release notes that came out. Some mention around logging and possibly improvements but does not give too much specifics. I will possibly update to 10.1.5 and let you know.

PAN-186725 - "Fixed an issue where index creation failed when Elasticsearch attempted to create a new index with a duplicate index name"

PAN-186516 - "Fixed an issue where log queries that included WildFire submission logs returned more slowly than expected"

PAN-184076 - "Fixed an issue on the firewall web interface where logs were delayed when querying for logs."

L3 Networker

I've seen the same slowness on the monitor tab since updating to 10.1.x

 

I plan on installing 10.1.5 on our 5220 this weekend and will update the thread if I see an improvement after.

dannon

 

L3 Networker

Updating PanOS to 10.1.5 on our 5520 fixed the slowness on the monitor tab for us.

We are currently on 10.1.5-h2 and the slowness has not come back.

Hello together,

I have a customer where the problem occured with the upgrade from 10.1.4 to 10.1.5-h1, 10.1.5-h2 did not fix the issue here.. Changing the retentiondays also does not fix the issue for us..

L1 Bithead

Hello,  I have the same Monitor Log tab slowness on a Panorama VM after upgrading from PAN-OS 10.0.10 to PAN-OS 10.1.6. I haven't yet upgraded the managed devices (physical and VMs). The PAN-OS 10.1 is not minimally reliable at all and I'm very worried too because PAN-OS 10.0.x EOL it's so close. I don't know if the Bugs founded in the Release Notes by @SpiroKU were fixed just for PA devices and not for Panorama. 

 

I've opened a case with TAC but after a week they haven't found a fix.

Hello Maur73G,

 

what helped by my customers was to downgrade and upgrade Pan-OS on the Panorama. (at least on M600-Devices) On the VMs I haven't come across that behaviour yet.

 

L1 Bithead

So update from me, upgraded to 10.1.5-H2. I mean, the logging seems slightly better but cant say it performs the same way as it did in PANOS 9.1 which is a shame. Also I have stopped relying on any data past 5 days. In addition, 10.1.5-H2 seems to have broken the global find where you expand objects, or well at least for me, and the generate certificate in the certificate store seems to place it in the wrong location in the running config (case opened with Palo Alto).

 

So, while it may be that upgrading fixes one thing, it breaks another. Wish I could downgrade but Palo Alto forces you to use 10.1 if you want Advanced URL filtering which too still shows as "License required for URL Filtering to function".

 

Regards.

Cyber Elite
Cyber Elite

Hello,

I would recommend 10.1.6. I have had issues with the 10.1.x-Hx fixes.

Regards,

L2 Linker

Has anyone had any luck with this?  We are still struggling through but this seriously impacts our ability to work effectively.  We're currently on 10.1.6-h6 but this has been going on since we upgraded into the 10.1 chain.  We sometimes have to wait for 10 minutes before a search will complete.  That's unacceptable, especially when you're in a troubleshooting call with multiple parties trying to find an issue.

 

Has anyone found any relief in later revisions of code?

If you have 220 or 850, you never getting this performance back. The Octane Processors used on those hardware are so slow. If you have something larger bigger, Go to new preferred release 10.1.9h3, its much better.  

 

If you talking about Panorama make sure after the upgrade you changed System disk to 224G instead of 81G. This was huge fix for us. Ref: https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/set-up-the-panorama-vi...

Santosh Patel
www.qnatech.com

I'll have to put an upgrade on the schedule for my 5220s.  Thanks for the reply Santosh!

L4 Transporter

Ive found 10.0.x and 10.1.x on gateways to be noticeably slower than 9.1 for log viewing and reporting. For Panorama, it is much worse. Almost unusable. I haven't tried 10.2 yet.

  • 11832 Views
  • 26 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!