Hello all!
We have had a single Panorama appliance running in Panorama mode as a local log collector in its own collector group. Firewall logs are sent to Panorama, and all is working well.
We now have procured a second Panorama appliance for HA. Hardware, disks etc., are all the same, and I've successfully set them up in HA, synced and healthy.
These two Panorama appliances are in different sites - though there is plenty of bandwidth and a few tens of ms latency between them. Currently, each appliance has only a single 2TB assigned to them. We don't plan to change from this setup or utilise dedicated log collectors anytime soon, and log retention fits within requirements.
The bit I am confused about is log collectors and collector groups. Cannot decide whether to have both appliances as either:
Single log collector per collector group
Put the secondary appliance in the same collector group as the primary appliance or multiple collectors in a single collector group.
Regarding multiple collectors in a collector group, I have read you can achieve redundancy, increase log retention and exceed logging rates. I am aware you need to check the box for enable log redundancy across collectors . I am also mindful that the logging rate is half - so I am not sure how the logging rates are exceeded if this happens?!
Regarding a single collector for each collector group, nothing seems to be mentioned or indicates anything about this. Why would I use this over multiple collectors in a single collector group? I know if the secondary appliance is down or lost, we lose those logs. I also assume you can still set the Log Forwarding Preferences list for both collectors in separate groups?
Hoping someone in this space can shed some light on what they have done or chime in on what you think!
Thank you for your time in reading and responding!
Panorama
... View more