PAN Syslog: Verifying the device is sending to all the configured

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PAN Syslog: Verifying the device is sending to all the configured

L3 Networker

I added an additional syslog destination on three of my PANs but I'm only seeing that traffic at an intervening PAN for two of the sources. I've used the troubleshooting methods noted here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClqICAS - but those are only showing me one syslog destination when four are configured. Are there other commands I can run to verify that the PAN is attempting to send to all of my configured syslog destinations?

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

@palomed "show logging-status" will show all type of log statistics, including logs beeing sent to log receiveres, etc. Otherwise you can check the following logs for detailed output regarding loging: 

 

> show log system direction equal backward subtype equal syslog

> less mp-log syslog-ng.log

View solution in original post

8 REPLIES 8

Community Team Member

Are you just wanting to get Firewall logs to different destinations?  Without Panorama?

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

I'm configuring the template/device/syslog from Panorama but I want the logging to head straight to the syslog server from the PANs themselves. I am trying to verify if this is working or not and those three commands in the URL I posted aren't telling me the needful.

L4 Transporter

@palomed "show logging-status" will show all type of log statistics, including logs beeing sent to log receiveres, etc. Otherwise you can check the following logs for detailed output regarding loging: 

 

> show log system direction equal backward subtype equal syslog

> less mp-log syslog-ng.log

show logging-status appears to show traffic forwarding on CMS 1.

 

Type Last Log Created Last Log Fwded Last Seq Num Fwded Last Seq Num Acked Total Logs Fwded
-----------------------------------------------------------------------------------------------------------------------------
> CMS 0
Panorama log forwarding agent is active
config Not Available Not Available 0 0 0
system Not Available Not Available 0 0 0
threat Not Available Not Available 0 0 0
traffic 2019/12/03 08:07:13 2019/12/03 08:07:15 4258462114 4258461428 686570724
hipmatch Not Available Not Available 0 0 0
gtp-tunnel Not Available Not Available 0 0 0
userid Not Available Not Available 0 0 0
auth Not Available Not Available 0 0 0

> CMS 1
Not Sending to CMS 1

>Log Collector
Not Sending to Log Collector

 

show log system direction equal backward subtype equal syslog

shows a connection to one syslog server destination

 

 less mp-log syslog-ng.log

shows logs all going to one destination although four are configured. And I can see that traffic is in fact

heading toward other syslog servers because I can see the flows in intervening firewalls.

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!