PA 5400 - No logs seen on the firewall including Traffic, URL filtering, Threat logs etc.

PA 5400 - No logs seen on the firewall including Traffic, URL filtering, Threat logs etc.

16092
Created On 10/05/21 09:46 AM - Last Modified 10/05/21 09:58 AM


Symptom


After deploying PA 5400 (PA 5450) series firewall there are no local logs seen under the Monitor tab.

Environment


PA 5400 series firewall.

Cause


  1. High-Speed-Log Forwarding Mode(HSFM) is by default enabled on the PA 5400 series firewalls while it is disabled by default in PA 7000 and PA 5200 series firewalls. 
  2. When HSFM is enabled, all local log storage is disabled. 
  3. Hence there will be no logs visible under the Monitoring tab. 




 


Resolution


Disable HSFM from GUI,
1. Device > Setup > Logging and Reporting Settings > Log Export and Reporting > [Uncheck] Enable High Speed Log Forwarding > OK
2. Commit the config.
User-added image

Disable HSFM from CLI.
admin@PA-5450> configure 
Entering configuration mode
[edit]                                                                                                                                                                                       
admin@PA-5450# set deviceconfig setting management enable-high-speed-log-forwarding no
[edit]                                                                                                                                                                                       
admin@PA-5450# commit
Once High Speed Log forwarding is disabled and config is committed, check the traffic logs to see if logs are starting to show up. 


Additional Information


  1. By default the logs will be written to the system disk storage. 
  2. For higher log retention period, extra logging disk will have to be installed on the firewall.
  3. This logging disk will have to be enabled to use it as the local logging disk. 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMaQCAU&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language