How to Increase Log Retention by Adding Disk to VM-Series

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to Increase Log Retention by Adding Disk to VM-Series

L1 Bithead

Hello,

We are currently running 28 Palo Alto VM-Series firewalls, deployed as 14 HA pairs (active/passive). Each firewall is hosted on a virtualized environment with standard disk allocation.

We heavily rely on traffic logs and threat logs for compliance purposes, and we're starting to hit retention limits due to limited disk capacity.

My Questions:

Is it officially supported to add additional virtual disks to VM-Series firewalls to increase log retention capacity?

If yes, what is the recommended process for adding and mounting the new disk?

Will PAN-OS automatically detect and use the added disk space?

Does the firewall need to be rebooted?

How do I safely expand log storage on each firewall without impacting the HA pair?

What are the best practices when working in active/passive HA mode?

Are there performance or stability concerns when increasing log storage significantly on VM-Series?

Thanks in advance.

King regards,

1 accepted solution

Accepted Solutions

You can add 1 additional disk, it will replace your current log partition (adding more disks has no impact)

The storage for each log type needs to be configured by setting the quota (device > setup > management > logging and reporting settings), so you control the retention by assigning enough disk% to the log you want to retain

You can use the default settings but i'm guessing you want to prefer certain types over others

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

here's a doc how to add a disk to the VM: 

https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-a-vm-series-firewall-on...

reboots are required so make sure you have a suitable maintenance window

 

have you considered connecting all your firewalls to the Strata Logging Service ? you'll have centralized logging for everything and you don't need to touch your VMs' disks and perform reboots and all that 🙂

bonus is centralized management via Strata Cloud Manager ('essentials' edition is free) if you want

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi @reaper 

 

 

Thank you very much for your response. I have a few follow-up questions:

If I add more disks, will the retention time automatically increase, or is manual configuration required to utilize the additional storage?

Is the adjustment to retention time handled automatically?

Will adding more disks have any impact on licensing?


Kind regards,

You can add 1 additional disk, it will replace your current log partition (adding more disks has no impact)

The storage for each log type needs to be configured by setting the quota (device > setup > management > logging and reporting settings), so you control the retention by assigning enough disk% to the log you want to retain

You can use the default settings but i'm guessing you want to prefer certain types over others

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 460 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!