Panorama. howto retrive old logs ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Panorama. howto retrive old logs ?

Not applicable

Hi,

I have panoram installed and configured. I have my PA FW that is now sending traffic logs and system logs, and threat logs to the Panorama.

1. How can I configure PA FW to send URL logs to the Panorama ?? as I do not see any url logs in the panoram from the PA FW ?

2. Panoram is now reading the current logs, how can I export the existing 1 month old logs from PA FW to panorama ?

Please advise.

Rgds,


Tauseef

1 ACCEPTED SOLUTION

Accepted Solutions

If you set up the firewall first and ran it for a a few weeks and then later installed Panorama then there is no way to export the old logs to Panorama. The best you can do is build a filter on the traffic monitor and then export to CSV but you will have to sift through this manually. You can submit this as a feature request if it is important to you.

Steve Krall

View solution in original post

8 REPLIES 8

L4 Transporter

Tauseef,

Check your profile and make sure you are sending "Informational" and "Low" level events. I believe the URL filtering alerst are considered informational. Also make sure your URL catagories are configured for ALERT or BLOCK. ANything configured for allow will not be logged.

Steve Krall

Hi Karl,

Thanks for this one, but my question was that when I had Panorama installed, already 40% logs were in the PA Firwall.

From the date I have configured the profile in PA for Panorama, all logs are being sent to the Panorama.

But the first 40% of logs that are in Palo Alto Firewall are still there in the same firewall.

How do I get the first 40% of these logs into the Panorama ??

If you set up the firewall first and ran it for a a few weeks and then later installed Panorama then there is no way to export the old logs to Panorama. The best you can do is build a filter on the traffic monitor and then export to CSV but you will have to sift through this manually. You can submit this as a feature request if it is important to you.

Steve Krall

Hi Karll,

How do I get the URL entries from the device to Panorama.

I know we have to set for 'informational or low', but its not working ! ((See attached log1)

I also tried creating a new rule and allowed only URL Alert, but still not working. (See Rule Alert)

Please advise.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!