Hello Lucas, Botnet Reporting is a threat prevention feature. The PAN collates information from traffic, threat, URL logs to identify botnet-infected hosts. The report generated each day consists a list of infected hosts, description(why we believe the host is infected) and a Confidence level. You can configure the parameters in addition to the query indicating what traffic you'd like to see the botnet report on. There are no Botnet logs, just predefined Botnet reports that run daily. However, you can configure botnet reports to be emailed out on daily basis according to your email server profile. Under Monitor > Botnet > Report setting You can then create report group to include that botnet report You can then create an email scheduler with email server profile to include that report group The above process who trigger an email (botnet report attached to it ) everyday to jdoe@xy.com Since there is nothing called botnet log, we cannot forward it to any external server. On another note, you can indeed forward your threat logs to external entities by following the document:How to Forward Threat Logs to Syslog Server Hope thats helps! Regards, Kunal Adak
... View more