Why are the firewall logs logged as 5 second interval?

Why are the firewall logs logged as 5 second interval?

297
Created On 01/11/24 02:01 AM - Last Modified 10/24/25 21:59 PM


Symptom


The dataplane logs (Traffic log, Threat log and etc) are logged at 5 second interval after upgrading PAN-OS 10.1.x or later.
Traffic log


Environment


  • PANOS-10.1 and above
  • Dataplane logs on all firewalls
  • Low logging rate


Cause


This is due to logging improvements made to logrcvr process since PAN-OS 10.1. The logrcvr process receives logs from DP.
We will only see this 5 second interval when log rate is extremely low, almost less than 32 logs/sec (depends on log size).


Resolution


In the current implementation, this interval is hardcoded. So you cannot change this behavior.
If logging rate is higher than 32 logs/sec (depends on log size), the log will be logged in a timely manner.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008WY5CAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail