Prisma Access commit failure due to validation error "Duplicate logging and Logging service cannot be enabled at the same time"

Prisma Access commit failure due to validation error "Duplicate logging and Logging service cannot be enabled at the same time"

2024
Created On 11/18/21 01:38 AM - Last Modified 12/01/23 02:38 AM


Symptom


Prisma Access commit failures with validation error as below.
<config-errors /><config-warnings /><details><line>Duplicate logging and Logging service cannot be enabled at the same time</line><line>Configuration is invalid</line></details></job></result>

 


Environment


  • Prisma Access managed by Panorama.
  • Any supported PanOS version

Note: The Panorama is also managing Strata firewalls which have Cortex Data lake licenses.


Cause


  • The Prisma Access environment does not support duplicate logging. 
  • This configuration is hidden from the user from Panorama in their respective templates.
  • The error is seen when the user tries to add another template in the Cloud service configuration that has duplicate logging enabled,
Example:
  • In this configuration DC2Template is added in the service setup configuration.
  • The panorama sends the template stack configuration to the cloud which includes the duplicate logging enabled parameter
  • This is unsupported for the Prisma Access.
GUI: Panorama> Cloud services> configuration
 
Templateconfig


Resolution


  1. Remove the Non Prisma Access template reference from the Prisma Access under GUI: Panorama > Cloud services> Configuration. (Example DC2Template in the above reference)  Or 
  2. Remove the duplicate logging config from this template.
  3. If the firewalls using DC2Template needs this configuration, enable this via another global template which is not referenced in the Prisma Access or Enable this config via individual firewall templates.
  4. Post removal of the invalid configuration parameter, the cloud service plugin does not present duplicate logging errors after commit.


Additional Information


The panorama is working as expected since the template and stack is designed to inherit the configuration.

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MNQCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail