This has popped up two or three times for me, in the first two it was running a fw that was a higher version than Panorama. My most recent example was running an older version of 8.0.x log collectors against a 8.1.x Panorama and 8.1.x FW. I would do a show logging-status to see if there is a misconfiguration and make note of the addresses. Take the results from the prior command: show netstat all yes | match 10.x.x.x It should look something like this: tcp your.firewall.com:50000 10.x.x.x:pan-panorama establshed If that looks fine, then I would logon to the Panorama CLI and run this command: show netstat all yes | match 3978 (may be 3798, not at a console) If it shows an active connection and you are running the exact same version on the fw, panorama or log collectors I would open a case with PA. I would verify the the time on all devices match and if using log collectors to make sure the dynamic updates are working and all are the same version, otherwise collation will not allow the logs to be processed. You can try and run this from Panorama to see if it can restart the connection. request log-fwd-ctrl device SERIALNUMBER start-from-lastack request log-fwd-ctrl device SERIALNUMBER action stop request log-fwd-ctrl device SERIALNUMBER action live request log-fwd-ctrl device SERIALNUMBER action start https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFCCA0 https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXACA0
... View more