Palo Alto Networks Knowledgebase: How to Setup Log Forwarding From Log Collector To Syslog Server

How to Setup Log Forwarding From Log Collector To Syslog Server

Created On 02/28/19 23:17 PM - Last Updated 02/28/19 23:35 PM
Log Collector Log Forwarding Logs M-100 Appliance System Log Device Management Policy Reporting and Logging 8.1 8.0 7.1 7.0 6.2 6.1 6.0 9.0 Cortex Data Lake PAN-OS Panorama

PAN-OS 6.0


Details About Log Forwarding

This document describes how to setup log forwarding from Log Collector in logger mode to Syslog Server. An M-100 log collector is always managed by a Panorama management server. The Panorama management server can either be a VM or an M-100 in Panorama mode.

Log collector Diagram

To access the Panorama Management server, perform the steps outlined below:

Step 1

Create a Syslog Profile 
– Go to Panorama > Server Profiles > Syslog, click Add and create a syslog profile, as shown below:

Screenshot of syslog profile

Step 2
Add a Collector Group. 
– Go to Panorama > Collector Groups and click Add.
– There are four tabs in the Collector Group window. For this configuration, go to Collector Log Forwarding.
– For details on adding devices to Collector Group and adding collectors to the group, please refer to this document: 

How to Configure an M-100 to Function as Both a Log Collector and Panorama.
– The Syslog Server profile can also be associated with Config, HIP Match, Traffic, Threat and WildFire.

Screenshot of Log Forwarding Set profile

Step 3
After the above step is done, proceed with the commit.
– First commit the changes to Panorama and then commit to the Collector Group. This is shown in the screenshot below.

Screenshot of log forwarding ssc

For more information about Log Forwarding, please see the following documents:

Configure Log Forwarding –
Objects > Log Forwarding –
Get Started with the Log Forwarding App –

owner: sodhegba

  • Print
  • Copy Link

Choose Language