Firewall does not send logs to Panorama even if log-collector preference-list is configured on the firewall

Firewall does not send logs to Panorama even if log-collector preference-list is configured on the firewall

5236
Created On 05/26/22 09:37 AM - Last Modified 05/25/23 03:31 AM


Symptom


  • CLI command  "show log-collector preference-list" on the firewall display the correctly configurated information.
> show log-collector preference-list
Log Collector Preference List
Forward to all: No
Serial Number: XXXXXXXX IP Address: X.X.X.X IPV6 Address: unknown
  • Similarly CLI command "show logging-status" also displays the correct information.
> show logging-status
---------------------------------------------------------------------------------------------------------
Type  Last Log Created   Last Log Fwded   Last Seq Num Fwded  Last Seq Num Acked      Total Logs Fwded
---------------------------------------------------------------------------------------------------------
> CMS 0
    Not Sending to CMS 0
> CMS 1
    Not Sending to CMS 1

>Log Collector 
'Log Collection log forwarding agent' is active and connected to X.X.X.X

config   2022/04/27 12:29:09   2022/04/27 12:35:57           18321        18002           955
system   2022/04/27 13:01:13   2022/04/27 13:01:28         3042639      2186527       2567599
threat   2022/04/27 13:01:13   2022/04/27 13:01:28         2010875      1526098       1444851
traffic   2022/04/27 00:08:48   2022/04/27 13:01:49     14619805453  12730810297     841339249
       .....(Output Omitted).....


  • When checking the logs on Panorama Monitor page, no logs are displayed.


Environment


  • Panorama configured as Log-collector.
  • PAN-OS 9.1 and above.
  • Firewall sending log to Log Collector.


Cause


  • Log collector configuration is not "pushed" to to Firewalls.
  • To check this information use the CLI command "show log-collector-group all" on Panorama
  • The Config Sync Status of  "Out of Sync", indicates the configuration procedure is not completed.
> show log-collector-group all

....(Output Omitted)
          Device FW-1-SN
               Log collector pref list PANORAMA-SN
          Device FW-2-SN
               Log collector pref list PANORAMA-SN


Log collectors in the group:

Serial       CID      Hostname         Connected   Config Status    SW Version         IPv4 - IPv6                                                     
--------------------------------------------------------------------------------------------------
PANORAMA-SN  2     PanoramaHostName      yes        Out of Sync      9.1.13             X.X.X.X - unknown

Redistribution status:       none
Last commit-all: commit succeeded, current ring version 0
SearchEngine status:    Unknown
...(Output omitted)....

 



Resolution


  1. Login Panorama WebUI
  2. On the right side top, Use drop down "Commit" button and select "Push to Devices" dialog
  3. Click on "Edit Selections"
  4. Click "Collector Groups" TAB
  5. Check the log-collector-name and click OK
  6. "Push" the configuration.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sYemCAE&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail