防火墙因断开连接而无法将日志上传到 Panorama。是否可以将它们迁移到 Panorama?

防火墙因断开连接而无法将日志上传到 Panorama。是否可以将它们迁移到 Panorama?

3041
Created On 12/19/24 08:11 AM - Last Modified 03/24/25 20:49 PM


Question


防火墙与Panorama一度断开连接,但连接已恢复。
然而,Panorama 中缺少某些时期的日志。
这些日志在防火墙的 GUI 上可见。是否可以将这些日志上传到 Panorama?



Environment


  • PAN OS 10.1、10.2、11.1、11.2
  • 日志转发至 Panorama
  • 下一代防火墙
  • 全景


Answer


Yes, it is possible.
Use the command below in firewall CLI for log migration to Panorama.

> request logdb migrate-to-panorama start end-time <value> start-time <value> type <value>

- end-time <value> : Datetime YYYY/MM/DD@hh:mm:ss (e.g. 2006/08/02@10:00:00)
- start-time <value> : Datetime YYYY/MM/DD@hh:mm:ss (e.g. 2006/08/01@10:00:00)
- type <value> : Log type (config, hipmatch, system, threat, traffic)

在防火墙CLI中使用以下命令检查迁移状态。

> request logdb migrate-to-panorama status type <value>

- type <value> : Log type (config, hipmatch, system, threat, traffic)

迁移的日志在 Panorama GUI 上可见。

[Executed Sample]

> request logdb migrate-to-panorama start end-time 2022/12/08@00:00:00 start-time 2022/12/07@00:00:00 type threat
Migration to LC started for type: threat
Check command 'request logdb migrate-to-panorama status' to check the status.

> request logdb migrate-to-panorama status type threat

Last log succesfully migrated timestamp: 2022/12/30 09:39:34
Migrating logs from (going backwards): 2022/12/08 00:00:00
Migrating logs until : 2022/12/07 00:00:00
Number of logs migrated: 10
Status: Migration going on
percent_complete: 10 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000TpQpCAK&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language