[need help]can't see new incoming logs after upgrading M-100 into 8.1.12

Reply
L4 Transporter

[need help]can't see new incoming logs after upgrading M-100 into 8.1.12

Originally my devices are:

-one M-100 with 7.1.10

-two PA-5020 (HA) with 7.1.10

-one PA-3050 with 7.1.9

all of three Palo Alto devices were registered to M-100 and forwarding logs were working fine.

 

I start upgrading M-100 first. 

From 7.1.10 to 8.0.20.

-upgrade is fine

-three devices are connecting after upgrade

-I know old format logs were not seen (as expected)... that's fine.

-new logs are seen on M-100

 

Next, when I upgrade M-100 from 8.0.20 to 8.1.12.

-upgrade is fine.

-three devices are connecting after upgrade

-[PROBLEM]I can't see new logs on M-100

-the output of 'show logging status' on both firewall and M-100 seems to be synched...which means the logs should be correctly forwarded to M-100

 

Anybody hit same issue?

What should I do to display new logs on M-100 v8.1.12 (all devices are v7.1.9 and v7.1.10 at this point)

 

Thank,

Emr

Cyber Elite

There were many changes in the 8.1 in terms of features sets and how Panorama is seen/used.

In pre 8.1, the Panorama only came up in Legacy mode.  In 8.1, I believe there is now a mode call Panorama mode.

When you look at your Dashboard on Panorama, what does it say?

 

Also, I think (strongly believe!!!) that you should be upgrading FWs to 8.1 or higher.

Both 8.0 and 7.x are now considered out of support, so you may not be able to contact support for  resolving this.

 

What other questions can we answer for you?

 

 

Help the community: Like helpful comments and mark solutions
L4 Transporter

@SteveCantwell 

Thanks for your reply.

My panorama is M-100, thus this only supports Panorama mode. (I believe Legacy mode is only for VM)

I'll share new findings today as below:::

 

I kept leaving my topology as I wrote above..today I found new logs from firewalls are stored to my M-100.

If I trace back my system log, start time of recording is at 0:00 GMT today.

 

Summarize my scenario:

 

Date Time(GMT) events

--------------------------------------

12/30 04:59 Management server started. Running version 8.1.12
12/30 05:02 Autocommit job succeeded
12/31 --:--
01/01 00:00 New logs start to be stored

 

The difference between upgrade is done and new logs are:

19hrs (rest of 30th)+24hrs(31st)=43hrs

 

Do you think this is expected behavior?

 

Note that I'm doing NOTHING to all of four (M-100 and three firewalls).

 

Regards,

Emr

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!