While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding from panorama to siem server facing system alert/log on

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding from panorama to siem server facing system alert/log on

L1 Bithead
Spoiler
Spoiler
While integrating panorama with SIEM server( using Syslog server profile ) for log forwarding from panorama to siem server facing system alert/log on panorama i.e “ panorama lost it is connection to peer, No logs will be forwarded ”
Panorama version- 10.2.4
Panorama is in HA but both peer have seperate log collector. 
Anyone has faced this same issue, please revert and help

Panorama

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello @prathamesh_s 

 

could you check logs from Panorama CLI to see it can give more details about root cause of the error: tail follow yes mp-log ms.log

 

Kind Regards

Pavel 

Help the community: Like helpful comments and mark solutions.

Hi , have run that command
 Output
Error: pan_comm_get_tcp_conn_gen (comm_utils.c:702 ) : COMM: connot connect. Remote ip= 172.24.*.* port=3978 err=connection timed out(110) sock 19
CMSA: Source bind sock to 172.20.*.*
COMM: Souce bind sock 19 to 172.20.*.* before connect to remote ip [172.24.*.*]  @port 3978

Note* = panorama is in HA , passive panorama in remote location. 
Active = 172.20.*.*
Passive= 172.24.*.*

Have run this command from active panorama 

Please reply

Cyber Elite
Cyber Elite

Hello @prathamesh_s

 

thank you for reply.

 

Regarding the first screen shot, it looks like that there is a connectivity issue between Panorama and managed Firewall. There is a time out for TCP 3978, but eventually at the end of the log, there is a message that device has registered. To me it looks like WAN / Connectivity issue. Could you check this KB: Troubleshooting Panorama Connectivity 

 

Regarding second screen shot with the error: "Panorama has lost...", it looks like a latency / connectivity issue between active and passive Panorama. The maximum recommended latency between both units should be below 500 ms. Here is a reference in documentation Doc. Since you mentioned that passive Panorama is in remote location, I would try to adjust HA Timers Doc.

 

Kind Regards

Pavel 

Help the community: Like helpful comments and mark solutions.
  • 2263 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!