- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-12-2026 12:53 PM
Hello All,
Planning an upgrade of a Panorama HA pair in management-only mode with two dedicated log collectors to PAN-OS 11.1.x from PAN-OS 10.2.x
To assist with the explanation below:
First, after reviewing the upgrade documentation (Upgrade Panorama in an HA Configuration ) for Panorama and the log collectors, I understand the upgrade procedure as:
My confusion arises from Upgrade Panorama Without an Internet Connection referencing the need to update the log collectors during the unit B upgrade process, which if you follow the thread would result in the log collectors being updated before unit A is upgraded. Is this an incorrect interpretation?
Second, if moving from version 10.2.x to 11.1.x, can I still skip PAN-OS versions on the log collectors (meaning the upgrade path would be directly 10.2.x to 11.1.x)?
Lastly, what happens to logs sent to log collectors when they are in the process of upgrading? Per Upgrade Log Collectors When Panorama Is Not Internet-Connected: log collectors must be upgraded simultaneously.
Any insight into these queries is much appreciated!
Cheers,
Nohash4u
03-13-2026 05:10 AM
- follow the process of upgrading panorama fully (both peers) before starting the collectors (there is a possibility of running the primary panorama upgraded and then upgrading the collectors before upgrading passive panorama, but why risk it)
- you can skip directly from 10.2. to 11.1
- while the log collector is unavailable, logs are queued on the firewalls until the collector is available again. unless your log volume is enormous, or the backbone between firewall and collector is already taxed (so log transfer is limited) you shouldnt lose any logs. there may be a bit of a delay in receiving 'live' logs while the firewall works through the backlog
03-13-2026 05:10 AM
- follow the process of upgrading panorama fully (both peers) before starting the collectors (there is a possibility of running the primary panorama upgraded and then upgrading the collectors before upgrading passive panorama, but why risk it)
- you can skip directly from 10.2. to 11.1
- while the log collector is unavailable, logs are queued on the firewalls until the collector is available again. unless your log volume is enormous, or the backbone between firewall and collector is already taxed (so log transfer is limited) you shouldnt lose any logs. there may be a bit of a delay in receiving 'live' logs while the firewall works through the backlog
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

