Hi Pavel,
thank you for the information and it very helpful.😀
i have additional question if you can help me to answer it.
Recently, we have tried implementing the solution of using Panorama as a local collector in our lab environment. We have built our lab environment using virtual machine (Panorama VM, Log Collector VM, and Firewall VM) and we are using Panos 10.1.8-h2.
We conducted several test scenarios:
1. All log collectors are UP.
2. LC1 is down, while the other is UP.
3. LC1 is back UP, and all devices are UP.
4. LC2 is down, while the other is UP.
5. LC2 is back UP, and all devices are UP.
With these scenarios, the obtained results are as follows:
1. When all log collectors are UP, the Firewall sends logs to LC1, and Panorama successfully queries and updates logs.
2. When LC1 is down, the Firewall sends logs to LC2. Panorama successfully queries logs, but the logs are not updating (stuck).
3. When LC1 is back UP, the Firewall resumes sending logs to LC1. Panorama successfully queries logs, and logs update normally.
4. When LC2 is down, the firewall continues to send logs to LC1. Panorama cannot query logs, resulting in a blank log monitor.
5. When LC2 is UP, the firewall still sends logs to LC1, and Panorama successfully queries logs and logs are updating.
Based on these results, I believe they do not align with what we expected, even though Panorama has been added as a local collector.
Is this behaviour is normal? Or is it that the solution cannot be applied in a virtual machine environment?
Thank you
... View more