Where are the administrator access logs on Panorama?

Reply
Highlighted
L2 Linker

Where are the administrator access logs on Panorama?

In Panorama where are the adminsitrator access logs? I.e. if I want to see when a adminsitrator user last accessed the system.  I know where that is on the PA firewalls, but on Panorama??

Tags (1)

Accepted Solutions
Highlighted
L2 Linker

Found it in case anybody else ever runs into this.  The "Device Grouping" view also changes the left hand menu as well, I didn't realize it was contextual; only though the information displayed on the side was device grouping dependent.

 

So in my case I needed "All" because Panorama itself isn't a device which can be grouped

View solution in original post


All Replies
Highlighted
L7 Applicator

You don't see it in system log?

 

panorama-admin-login.PNG

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE, PCNSE, PCNSI
Highlighted
L7 Applicator

did you enable system log forwarding ?

system log forwarding.png

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Highlighted
L2 Linker

Raido: LOL I don' t even have that option on my Panorama system (though I do on my PA's):

 

Capture.PNG

Highlighted
L2 Linker

reaper: Yes though I assume it still keeps local logs (as I don' t have access to where the logs are actually forwarded to; don't ask, org politics)

Highlighted
L7 Applicator

Hi @PeterT then it would appear your admin account does not have access to these logs (physically or through the GUI)

 

your only recourse will be to use the context switch to look at the local logs on the firewall

 

 

 

Quis custodiet ipsos custodes ;)

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Highlighted
L2 Linker

@reaper That makes no sense given I'm logged on as the "superuser" on the Panorama :) .. i.e. have rights to everything, I just don't have rights to the Arcsight SIEM where the remote logs are dumped ;) .  I should still be able to see the panorama local access logs though IMHO as would be a wierd situation where the panorama superuser could see the logs on the FW's (which I can) but not panorama itself

Highlighted
L7 Applicator

well that's awkward :p

 

ehm, what version of PAN-OS are you running? those log files should be there... can you try checking the CLI ?

 

> show log config direction equal backward
> show log system direction equal backward
Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Highlighted
L2 Linker

Panorama 8.0.2

 

Both work via CLI, the question then (per screenshot above) where is it via the Web UI?  I'm thinking possibly bug / call support on this one now lol.

L7 Applicator

yeah... if you're superuser those logs should be visible...

one last thing you could try (before calling support) is to 'reset' the gui : https://<panorama IP>/debug

 

once logged in, click the 'clear preferences' button, this will clear your admin's gui config, in case some flag got set

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!