Log Collector Redundancy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Log Collector Redundancy

L1 Bithead

I have a client with a Panorama HA Pair that spans facilities via DWDM. It's fast enough (sub 10ms) to run an LCG that spans both DCs, but this is still poor design as it effectively halves the MTBF (you're now dependent on both members of a 2-node cluster to be operational thanks to the Elasticsearch quorum).

 

So we run 2 independent LCGs to improve overall availability of each LC, which also minimises log traffic over the DCI by including only the local devices in each LCG's preference list.

 

The only challenge with this approach, or any Panorama HA pair for that matter, is that there is no redundancy in the log collection layer without introducing 2 additional collectors at each site (since we don't want an LCG to span facilities). If a Panorama instance fails, the devices logging to that instance buffer until it's available.

 

Is there a way to achieve redundant log collection in a Panorama HA pair without increasing the deployment footprint?

1 accepted solution

Accepted Solutions

Cyber Elite

the short answer, no: you need 3 collectors to form a LCG

you could consider Strata Logging Service, which would take away the redundancy concerns

Tom Piens
PANgurus - Strata & Prisma Access specialist

View solution in original post

2 REPLIES 2

Cyber Elite

the short answer, no: you need 3 collectors to form a LCG

you could consider Strata Logging Service, which would take away the redundancy concerns

Tom Piens
PANgurus - Strata & Prisma Access specialist

Thanks for confirming Tom, I had figured that. It's an air-gapped network and the devices will log in parallel to a local SIEM, so 2x 1 member LCGs is still acceptable. In this case the SIEM provides the redundancy and retention required for compliance.

 

Appreciate your help.

  • 1 accepted solution
  • 785 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!