Hello All,
1.) I have just installed Palo Alto 7.1 in Eve-NG, and made two interfaces as Vwire with zone Trust and Untrust.
2.) I am able to access access everthing (e.g. internet, ping, etc.) hence policies are working fine as I have created a policy to allow everything from Trust to Untrust.
However I am not able to see any Traffic logs in the GUI it is blank.
Kindly see the below screenshot for your reference and let me know what's the reason please.
Thanks in advance.
This may sound obvious but make sure you are enabling the logging on the security policies your traffic is hitting. you can log at session start and or sesssion end.
Hello,
Also the default intra and inter zone policies do not log so you have to set them to log as well.
Regards,
Yes i agree with Okta.
Hello,
Does anybody got a resolution? I have the same problem with a PA in EVE-NG. Tried 2 different images. thank you
Same issue, logs are not showing in GUI and as well as CLI but logs are being written.
admin@PA-VM> show log traffic
Time App From Src Port Source
Rule Action To Dst Port Destination
Src User Dst User End Reason
Rule_UUid
====================================================================================================
admin@PA-VM> debug log-receiver statistics
Logging statistics
------------------------------ -----------
Log incoming rate: 1/sec
Log written rate: 1/sec
Corrupted packets: 0
Corrupted URL packets: 0
Corrupted HTTP HDR packets: 0
Corrupted HTTP HDR Insert packets: 0
Corrupted EMAIL HDR packets: 0
Logs discarded (queue full): 0
Traffic logs written: 120
I read that the VM needs to be licensed for monitoring, clustering and some other features to work. Not sure if it’s true
Yes the VM needs to be licensed,
but you can still see some logs over
Policies>security> "click on your rule" > usage
Or- from CLI
> show session all
thanks!
did you find a solution, I have the same problem...
Palo doesn't log on VM PAN OS without license...
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm2mCAC
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!