Firewall does not send logs to Panorama even if log-collector preference-list is configured on the firewall
5236
Created On 05/26/22 09:37 AM - Last Modified 05/25/23 03:31 AM
Symptom
- CLI command "show log-collector preference-list" on the firewall display the correctly configurated information.
> show log-collector preference-list
Log Collector Preference List
Forward to all: No
Serial Number: XXXXXXXX IP Address: X.X.X.X IPV6 Address: unknown
- Similarly CLI command "show logging-status" also displays the correct information.
> show logging-status
---------------------------------------------------------------------------------------------------------
Type Last Log Created Last Log Fwded Last Seq Num Fwded Last Seq Num Acked Total Logs Fwded
---------------------------------------------------------------------------------------------------------
> CMS 0
Not Sending to CMS 0
> CMS 1
Not Sending to CMS 1
>Log Collector
'Log Collection log forwarding agent' is active and connected to X.X.X.X
config 2022/04/27 12:29:09 2022/04/27 12:35:57 18321 18002 955
system 2022/04/27 13:01:13 2022/04/27 13:01:28 3042639 2186527 2567599
threat 2022/04/27 13:01:13 2022/04/27 13:01:28 2010875 1526098 1444851
traffic 2022/04/27 00:08:48 2022/04/27 13:01:49 14619805453 12730810297 841339249
.....(Output Omitted).....
- When checking the logs on Panorama Monitor page, no logs are displayed.
Environment
- Panorama configured as Log-collector.
- PAN-OS 9.1 and above.
- Firewall sending log to Log Collector.
Cause
- Log collector configuration is not "pushed" to to Firewalls.
- To check this information use the CLI command "show log-collector-group all" on Panorama
- The Config Sync Status of "Out of Sync", indicates the configuration procedure is not completed.
> show log-collector-group all
....(Output Omitted)
Device FW-1-SN
Log collector pref list PANORAMA-SN
Device FW-2-SN
Log collector pref list PANORAMA-SN
Log collectors in the group:
Serial CID Hostname Connected Config Status SW Version IPv4 - IPv6
--------------------------------------------------------------------------------------------------
PANORAMA-SN 2 PanoramaHostName yes Out of Sync 9.1.13 X.X.X.X - unknown
Redistribution status: none
Last commit-all: commit succeeded, current ring version 0
SearchEngine status: Unknown
...(Output omitted)....
Resolution
- Login Panorama WebUI
- On the right side top, Use drop down "Commit" button and select "Push to Devices" dialog
- Click on "Edit Selections"
- Click "Collector Groups" TAB
- Check the log-collector-name and click OK
- "Push" the configuration.