防火墙因断开连接而无法将日志上传到 Panorama。是否可以将它们迁移到 Panorama?
3041
Created On 12/19/24 08:11 AM - Last Modified 03/24/25 20:49 PM
Question
防火墙与Panorama一度断开连接,但连接已恢复。
然而,Panorama 中缺少某些时期的日志。
这些日志在防火墙的 GUI 上可见。是否可以将这些日志上传到 Panorama?
Environment
- PAN OS 10.1、10.2、11.1、11.2
- 日志转发至 Panorama
- 下一代防火墙
- 全景
Answer
Yes, it is possible.
Use the command below in firewall CLI for log migration to Panorama.
> request logdb migrate-to-panorama start end-time <value> start-time <value> type <value>
- end-time <value> : Datetime YYYY/MM/DD@hh:mm:ss (e.g. 2006/08/02@10:00:00)
- start-time <value> : Datetime YYYY/MM/DD@hh:mm:ss (e.g. 2006/08/01@10:00:00)
- type <value> : Log type (config, hipmatch, system, threat, traffic)
在防火墙CLI中使用以下命令检查迁移状态。
> request logdb migrate-to-panorama status type <value>
- type <value> : Log type (config, hipmatch, system, threat, traffic)
迁移的日志在 Panorama GUI 上可见。
[Executed Sample]
> request logdb migrate-to-panorama start end-time 2022/12/08@00:00:00 start-time 2022/12/07@00:00:00 type threat
Migration to LC started for type: threat
Check command 'request logdb migrate-to-panorama status' to check the status.
> request logdb migrate-to-panorama status type threat
Last log succesfully migrated timestamp: 2022/12/30 09:39:34
Migrating logs from (going backwards): 2022/12/08 00:00:00
Migrating logs until : 2022/12/07 00:00:00
Number of logs migrated: 10
Status: Migration going on
percent_complete: 10