Hello @Chris80
you will have to perform below steps.
1.)
Register Firewall to Panorama (Add Firewall's S/N + Authentication key).
2.)
Theoretically, it is not necessary to add Firewall to Device Group to get logs only, however I recall memory that logs did not show up until I associated Firewall with Device Group. Please test it first by not associating Firewall with Device Group. If logs do not show up after completing all the steps, please add Firewall to Device Group to see logs show up.
3.)
Add Firewall to log collector group by navigating to: Panorama > Collector Groups > [Log Collector Name] > Device Log Forwarding > Log > Forwarding Preference.
4.)
Commit configuration to Panorama and to log collector. If you do not push configuration to log collector group logs will not show up. To see the logs you do not have to push Device Group configuration, but if you have assigned Firewall to for example dummy Device Group with no actual configuration in it, the Firewall will be reporting out of sync status, however this should not prevent Firewall from sending logs to Panorama.
5.)
On Firewall side, in log forwarding profile select log Forwarding Method "Panorama" checkbox.
After completing all steps you should see Firewall logs coming without having Panorama managing Firewall configuration. There are a few things to keep in mind. If your Firewall and Panorama are using different Time/Time Zone logs might not show up in Panorama's GUI. Ideally you should sync time with the same NTP server.
Kind Regards
Pavel
... View more