Today your option is to setup dual-logging at each PA-device. That is it has one feed towards Panorama and one feed towards your syslog/SIEM. This syslog-feed can also be manually setup in case you only care for a few "columns", or for that matter using CEF format if your SIEM supports that format. Tomorrow hopefully Feature Request ID 782 (tell your sales engineer to add your company to this ID) will be taken care of which means that Panorama will be able to not only forward the logs the Panorama itself created but also "relay" any incoming logs from the PA-devices. This way (since Panorama uses some kind of delivery secured method) the PA devices will only have to log once (compared to twice as today) and if the connection with Panorama is lost the logs will not be lost (as with syslog which sends out to devnull) but buffered on the PA device until Panorama returns and then fetches whatever logs were produced while the link between the PA and Panorama was down.
... View more