Hello again all,
My next hurdle is figuring out why my VM-Series firewalls aren't getting their logs to the panorama server.
I've checked the following soo far:
Network path between the firewalls and panorama look good. it's allowing ICMP and all TCP.
Managed collectors (local to this panorama an an HA panorama) show green, in sync, green health status.
There's just one collector group with with both of those collectors in it
I've added the VM-series firewalls into the Device log forwarding section on the collector group
In the firewall policies, there is traffic hitting them and the action is set to log and forward to a log forwarding profile
log forwarding profile has objects to forward all traffic and threat logs to panorama.
I'm unaware if I'm issuing any configuration points in the above.
If I go to the firewall and run a "debug management-server log-collector-agent-status" there are no agents listed. If I run a "show logging-status", I see a variety of collectors but they are all in a "lr - Inactive" state under connection status.
Any idea what I'm missing?
... View more