No logs in the monitor > traffic tab?

Reply
Highlighted
L0 Member

No logs in the monitor > traffic tab?

Hello All,


1.) I have just installed Palo Alto 7.1 in Eve-NG, and  made two interfaces as Vwire with zone Trust and Untrust.

2.) I am able to access access everthing (e.g. internet, ping, etc.) hence policies are working fine  as I have created a policy to allow everything from Trust to Untrust.

 

However I am not able to see any Traffic logs in the GUI it is blank.

Kindly see the below screenshot for your reference and let me know what's the reason please.

no logs.png


Thanks in advance.

Highlighted
L4 Transporter

Re: No logs in the monitor > traffic tab?

This may sound obvious but make sure you are enabling the logging on  the security policies your traffic is hitting. you can log at session start and or sesssion end. 

Highlighted
L7 Applicator

Re: No logs in the monitor > traffic tab?

Hello,

Also the default intra and inter zone policies do not log so you have to set them to log as well.

 

Regards,

Highlighted
L4 Transporter

Re: No logs in the monitor > traffic tab?

Yes i agree with Okta.

MP
Highlighted
L0 Member

Re: No logs in the monitor > traffic tab?

Hello,

Does anybody got a resolution? I have the same problem with a PA in EVE-NG. Tried 2 different images. thank you

Highlighted
L0 Member

Re: No logs in the monitor > traffic tab?

Same issue, logs are not showing in GUI and as well as CLI but logs are being written.

 

admin@PA-VM> show log traffic
Time App From Src Port Source
Rule Action To Dst Port Destination
Src User Dst User End Reason
Rule_UUid
====================================================================================================
admin@PA-VM> debug log-receiver statistics

Logging statistics
------------------------------ -----------
Log incoming rate: 1/sec
Log written rate: 1/sec
Corrupted packets: 0
Corrupted URL packets: 0
Corrupted HTTP HDR packets: 0
Corrupted HTTP HDR Insert packets: 0
Corrupted EMAIL HDR packets: 0
Logs discarded (queue full): 0
Traffic logs written: 120

 

Highlighted
L0 Member

Re: No logs in the monitor > traffic tab?

I read that the VM needs to be licensed for monitoring, clustering and some other features to work. Not sure if it’s true

Highlighted
L0 Member

Re: No logs in the monitor > traffic tab?

Yes the VM needs to be licensed, 

but you can still see some logs over 

 

Policies>security> "click on your rule" > usage 

 

Or-  from CLI 

> show session all 

 

thanks!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!