- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-05-2022 12:21 AM
Recently we created a new template with different server profiles and log settings in Panorama and tried validating in the target firewalls but it throws the validation error. Looking for the experts advise to address this issue.
Panorama is on PAN OS version 9.1.10
Affected Firewalls are running on PAN OS version 8.1.13
Validation Error:
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-traffic -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-traffic -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-info -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-info -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-info -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-info -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-data-info -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-data-info -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-low -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-low -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-low -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-low -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-data-low -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-data-low -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-med -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-med -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-med -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-med -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-data-med -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-data-med -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-hi -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-hi -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-hi -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-url-hi -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-cr -> send-syslog 'Live_Log_Collectors' is not a valid reference
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list -> Live_Log_Forwa-threat-cr -> send-syslog is invalid
. vsys -> vsys1 -> log-settings -> profiles -> Live_Log_Forwarding -> match-list is invalid
. vsys -> vsys1 -> log-settings -> profiles is invalid
. vsys -> vsys1 -> log-settings is invalid
. vsys is invalid
. devices is invalid
. shared -> log-settings is invalid
. shared is invalid
. Configuration is invalid
05-10-2022 05:24 PM
Thank you for the post @Kathiravan_R
the issue you reported is hard to troubleshoot over forum. Myself when I face issues like this, I sometimes narrow down the root cause by try & error approach, however the first thing that comes to my mind is the dependency between Device Group and Template Stack configurations. The syslog server: Live_Log_Collectors is configured in Template while log forwarding profile is configured under Device Group. The first thing I would try is to roll back the change and first push the Template Stack where you configured the syslog server: Live_Log_Collectors. If this does not give any error, then in the Device Group add Live_Log_Collectors to log forwarding profile and push Device Group to firewall.
Kind Regards
Pavel
05-17-2022 06:53 AM
@PavelK Thank you for looking into this issue.
New template is accepting in remaining firewalls(PA-5050) without any issue however a pair of PA-5050 is not accepting the template and throws the validation error. We are able to push the security policies to those firewalls but template validation fails. Any recommendation and helps are highly appreciated.
06-12-2022 03:52 PM
I am sorry for getting back to you with delay @Kathiravan_R
After you get the validation error, could you check logs from CLI on both Panorama as well as managed Firewall whether it can give more details what the issue is: tail lines 500 mp-log configd.log
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!