how to check from how many days logs are stored in palo alto firewall?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

how to check from how many days logs are stored in palo alto firewall?

L0 Member

Hello team I am a new user of Palo Alto FW device.
1)please let me know how to check from last how many days logs are stored in the Palo Alto firewall.
2)How to access the very first logs stored in the device?

3)what is the retention period of these logs??

Thank you.

1 REPLY 1

Cyber Elite
Cyber Elite

1)please let me know how to check from last how many days logs are stored in the Palo Alto firewall.

If you look at the CLI you can view the oldest logs on the device by simply running 'show log <type> direction equal backward' to get the logs in ascending order (IE: the oldest logs displayed first). Likewise on the GUI you would simply click into the logs and towards the bottom right you'll see it defaulting to 'DESC' (descending) and you'll want to modify it to 'ASC' (ascending).  While the firewall does age off logs according to your 'Max Days' setting, this age-out value isn't cleanly presented in what you're likely expecting.

 

2)How to access the very first logs stored in the device?

See above

 

3)what is the retention period of these logs??

Whatever you have it configured to retain or when the assigned storage quota is utilized and it starts deleting the oldest logs.

 

You have the ability to manage all of this under Device -> Setup -> Management if you scroll to the bottom of that page on the left you'll see the 'Logging and Reporting Settings' tab. This is where you allocate disk space to each log type, specify the max number of days the firewall should retain logs, along with what you want to do if your out of log space.

By default, the firewall doesn't have any retention period configured. It will have space allocated that favors Traffic and Threat logs, but it doesn't have a max days default from a retention period unless you as the administrator configure one. Likewise, the default action will have the firewall simply aging off the oldest logs as you run out of quota space for each type of logs. Just because you specify 30 'Max Days' on your traffic logs as an example, if you don't have enough space you won't actually be maintaining all 30 days of traffic logs.

  • 2752 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!