- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-16-2024 07:19 PM
Hello team I am a new user of Palo Alto FW device.
1)please let me know how to check from last how many days logs are stored in the Palo Alto firewall.
2)How to access the very first logs stored in the device?
3)what is the retention period of these logs??
Thank you.
03-16-2024 07:46 PM
1)please let me know how to check from last how many days logs are stored in the Palo Alto firewall.
If you look at the CLI you can view the oldest logs on the device by simply running 'show log <type> direction equal backward' to get the logs in ascending order (IE: the oldest logs displayed first). Likewise on the GUI you would simply click into the logs and towards the bottom right you'll see it defaulting to 'DESC' (descending) and you'll want to modify it to 'ASC' (ascending). While the firewall does age off logs according to your 'Max Days' setting, this age-out value isn't cleanly presented in what you're likely expecting.
2)How to access the very first logs stored in the device?
See above
3)what is the retention period of these logs??
Whatever you have it configured to retain or when the assigned storage quota is utilized and it starts deleting the oldest logs.
You have the ability to manage all of this under Device -> Setup -> Management if you scroll to the bottom of that page on the left you'll see the 'Logging and Reporting Settings' tab. This is where you allocate disk space to each log type, specify the max number of days the firewall should retain logs, along with what you want to do if your out of log space.
By default, the firewall doesn't have any retention period configured. It will have space allocated that favors Traffic and Threat logs, but it doesn't have a max days default from a retention period unless you as the administrator configure one. Likewise, the default action will have the firewall simply aging off the oldest logs as you run out of quota space for each type of logs. Just because you specify 30 'Max Days' on your traffic logs as an example, if you don't have enough space you won't actually be maintaining all 30 days of traffic logs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!