12-02-2019 11:02 AM
I added an additional syslog destination on three of my PANs but I'm only seeing that traffic at an intervening PAN for two of the sources. I've used the troubleshooting methods noted here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClqICAS - but those are only showing me one syslog destination when four are configured. Are there other commands I can run to verify that the PAN is attempting to send to all of my configured syslog destinations?
12-03-2019 01:42 AM
@palomed "show logging-status" will show all type of log statistics, including logs beeing sent to log receiveres, etc. Otherwise you can check the following logs for detailed output regarding loging:
> show log system direction equal backward subtype equal syslog
> less mp-log syslog-ng.log
12-02-2019 04:12 PM
Are you just wanting to get Firewall logs to different destinations? Without Panorama?
12-02-2019 04:15 PM
I'm configuring the template/device/syslog from Panorama but I want the logging to head straight to the syslog server from the PANs themselves. I am trying to verify if this is working or not and those three commands in the URL I posted aren't telling me the needful.
12-03-2019 01:42 AM
@palomed "show logging-status" will show all type of log statistics, including logs beeing sent to log receiveres, etc. Otherwise you can check the following logs for detailed output regarding loging:
> show log system direction equal backward subtype equal syslog
> less mp-log syslog-ng.log
12-03-2019 08:29 AM
show logging-status appears to show traffic forwarding on CMS 1.
Type Last Log Created Last Log Fwded Last Seq Num Fwded Last Seq Num Acked Total Logs Fwded
-----------------------------------------------------------------------------------------------------------------------------
> CMS 0
Panorama log forwarding agent is active
config Not Available Not Available 0 0 0
system Not Available Not Available 0 0 0
threat Not Available Not Available 0 0 0
traffic 2019/12/03 08:07:13 2019/12/03 08:07:15 4258462114 4258461428 686570724
hipmatch Not Available Not Available 0 0 0
gtp-tunnel Not Available Not Available 0 0 0
userid Not Available Not Available 0 0 0
auth Not Available Not Available 0 0 0
> CMS 1
Not Sending to CMS 1
>Log Collector
Not Sending to Log Collector
show log system direction equal backward subtype equal syslog
shows a connection to one syslog server destination
less mp-log syslog-ng.log
shows logs all going to one destination although four are configured. And I can see that traffic is in fact
heading toward other syslog servers because I can see the flows in intervening firewalls.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!