Traffic, Threat and URL filtering logs are not displayed on the Firewall.

Traffic, Threat and URL filtering logs are not displayed on the Firewall.

57123
Created On 05/01/19 03:02 AM - Last Modified 03/20/25 03:21 AM


Symptom


URL Filtering, Threat and Traffic logs are not visible on the firewall.

Environment


  • Firewall platform
  • Supported PAN-OS releases
  • Logging
  • Netflow enabled


Cause


  • Neflow is enabled on the interface.
  • PAN-OS logs experience a significant delay before they are displayed if NetFlow  is enabled on an interface. This information is documented under PAN-215869
  • The global counters (show counter global) display the traffic loss count. 
Traffic log counters:
log_traffic_loss_cnt            Number of traffic logs that are lost
log_traffic_loss_queue_full     Number of traffic logs that are lost due to next queue is full
Threat logs global counters:
log_threat_queue_full          Number of threat log queues that is full
log_threat_loss_cnt            Number of threat logs that are lost


Resolution


To resolve this issue, the logging rate needs to be reduced. Here are the different ways of achieving the same.

Option1:

  1. Reduce the amount of NetFlow traffic pulled from the NetFlow collector to allow the firewall to recover.
  2. This action will decrease the amount of NetFlow logs.

Option2:

  1. Reduce the amount of traffic the firewall needs to categorize for URL filtering. This can be done by changing the alert setting which generates logs.
  2. This action will decrease the amount of Threat logs.

Option3:

  1. Turn off "Log at Session Start" from security policies.
  2. This action will decrease the amount of Traffic logs.
  3. Refer to the article Session Log Best Practices for more information.


Additional Information


Troubleshooting loss of dataplane logs on the Firewall



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLt5CAG&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language