Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 4991 Views
  • 0 replies
  • 0 Likes

Resolved! Device Group "Shared" available in Policies tab but missing in Objects tab

Hi all, I've run into something confusing in Panorama and wanted to check if this is expected behavior or a bug on my end. When I go to the Policies tab, I can select Device Group: Shared from the dropdown without any issue. However, when I switch to the Objects tab and open the Device Group selector there, "Shared" is not listed at all — I can'...

MaratP by L1 Bithead
  • 132 Views
  • 2 replies
  • 1 Likes

IDS Alerts

Hi, I have been by auditors to submit IDS log alerts from Panorama, i know the best practice is to use Microsoft Sentinel. Has anyone done directly using Panorama and which severity is selected to minimize impact on the smtp server.

GlobalProtect Logs Showing Only a Few Days of Retention on Panorama

Hello Community, We are experiencing an issue with GlobalProtect log retention on Panorama. Our Panorama manages 6 firewalls, and all firewalls are configured to forward logs to Panorama. However, on Panorama, the GlobalProtect logs for the managed firewalls are only retained for about 6 days. When we check the output of the command show sys...

Panorama Virtual Appliance on Azure – Admin Password Recovery (No SSH Key)

Hi everyone, I'm looking for guidance on how to recover admin access to a Panorama virtual appliance deployed on Microsoft Azure where the admin password has been lost. **Environment:**- Panorama Virtual Appliance on Microsoft Azure- Authentication configured with username/password only (no SSH key pair was configured at deployment time)- No o...

Improve log filtering workflow with quick “exclude / NOT filter” option from Traffic logs

Hi team, I’d like to suggest a small but impactful improvement to the Traffic Logs filtering workflow. Today, when we click on a value in a log entry (e.g. source IP, destination IP, user, etc.), it automatically adds that value to the search bar as a positive filter (e.g. eq / in). This is extremely useful and significantly speeds up building...

Resolved! Link to Panorama demo site

Hi All I have the link to the PAN Firewall demo site (https://us1.demo.paloaltonetworks.com) but have forgotten the URL link to the Panorama demonstration site, can someone please help or direct me to the correct Panorama link.

Impossible to migrate an ae interface to a different speed in Panorama?

Quite new to Panorama, but have been working with Palo Alto standalone firewalls for a little while. Client has 2 Active Passive HA FW's in Panorama and an ae1 interface with 4x 1G interfaces as members. They want to switch this to 4x of the 10G interfaces during an outage window. Am I right that I should be able to just remove the 4x 1G membe...

Can we create a custom log forwarding to syslog server for PAN OS greater then 11.0.0

In our Panorama syslog forwarding we can see logs are sent in the Default Format . We need to change it to a customized format . Default Format :<14>May 27 20:07:50 FW1 1,2026/05/27 20:07:49,016201049542,CONFIG,0,2562,2026/05/27 20:07:50,10.252.40.134,,set,ADMCREGT,Web,Succeeded, deviceconfig high-availability group,7618904982443524109,0x8...

Load various configuration onto staged firewall from panorama for a few attempts - remote install

Hi, i have a panorama connected firewall in a staging build room. I need to take it to a remote site and connect it to a Starlink connection (which is already mounted). Is it possible to push down a few different configuration options to the firewall so that when I'm in the remote location if my main config does't form a connection and I need to...

Resolved! resolve hostname in logs now working in panorama

The "Resolve Hostname" feature can resolve the ip address in a log entry to the corresponding hostname using the address objects configured on the firewall or by doing a DNS lookup. When this box is checked, the firewall tries to resolve the ip addresses in the logs to the corresponding hostnames. When the checkbox is selected, the device will f...

ET by L3 Networker
  • 542 Views
  • 1 replies
  • 0 Likes

No way to use target to send an op command to a firewall from Panorama using the supported Ansible modules?

I can do this by calling the API manually, but I can't seem to use the operation command module. curl --location --globoff 'https://<Panorama-IP>/api/?type=op&cmd=<show><system><info></info></system></show>&target=0123456789&key=<your-api-key>' Skrting the issue in Ansible: - ...

Eric_B by L1 Bithead
  • 764 Views
  • 2 replies
  • 0 Likes
  • 720 Posts
  • 47 Subscriptions
Top Solution Authors
Labels