Palo Alto Networks Knowledgebase: Panorama/Firewall do not populate 'Region' while enabling Logging-service option

Panorama/Firewall do not populate 'Region' while enabling Logging-service option

Created On 07/17/19 21:11 PM - Last Updated 07/17/19 22:30 PM
Device Management Initial Configuration Installation QoS Zone and DoS Protection

While configuring firewalls to forward logs to the logging service based on the steps provided in the following document, you might run into an issue where the drop-down for 'Region' is empty and won't display the region on the Panorama and the firewall.


This is a mandatory step in the configuration to enable log forwarding to the logging-service [Step 4] :-



Screen Shot 2018-05-30 at 3.44.20 PM.png


Logs :


The firewall will show the following error when you attempt to see customerinfo :


Screen Shot 2018-05-30 at 3.43.33 PM.png


lcaas_agent.log for logging-service shows '502 Bad Gateway' error :


Screen Shot 2018-05-30 at 3.47.37 PM.png



To fix this :


You will need to enable the 'Region' on the Panorama CLI using the following command :-


> Login to Panorama CLI
> enter configure mode using the command ">configure"
> run "set template <template_name> config deviceconfig setting logging logging-service-forwarding enable yes logging-service-regions <region>"
> commit 


<template_name> is the template the device is part of.

<region> can be americas, europe, etc


> Then, push the changes to the firewall. Verify Device > Setup > Management page to make sure the Region populates correctly.



  • Print
  • Copy Link

Choose Language