©
Palo
Alto
Networks,
Inc.
Panorama
6.1
Administrator’s
Guide
•
123
Manage
Log
Collection
Modify
Log
Forwarding
and
Buffering
Defaults
Modify
Log
Forwarding
and
Buffering
Defaults
You
can
define
the
log
forwarding
mode
that
the
firewalls
use
to
send
logs
to
Panorama
and
when
configured
in
a
high
availability
configuration,
specify
which
Panorama
peer
can
receive
logs.
To
access
these
options,
select
Panorama > Setup > Management
,
edit
the
Logging
and
Reporting
Settings,
and
select
the
Log Export and
Reporting
tab.
Define
the
log
forwarding
mode
on
the
firewall:
The
firewalls
can
forward
logs
to
Panorama
(pertains
to
both
the
M
‐
100
appliance
and
the
Panorama
virtual
appliance)
in
either
Buffered
Log
Forwarding
mode
or
in
the
Live
Mode
Log
Forwarding
mode.
Define
log
forwarding
preference
on
a
Panorama
virtual
appliance
that
is
in
a
high
availability
(HA)
configuration:
–
When
logging
to
a
virtual
disk,
enable
logging
to
the
local
disk
on
the
Active
‐
Primary
Panorama
peer
only.
By
default,
both
Panorama
peers
in
the
HA
configuration
receive
logs.
–
When
logging
to
an
NFS,
enable
the
firewalls
to
send
only
newly
generated
logs
to
a
secondary
Panorama
peer,
which
is
promoted
to
primary,
after
a
failover.
Logging
Options
Description
Buffered Log Forwarding from
Device
Default:
Enabled
Allows
each
managed
firewall
to
buffer
logs
and
send
the
logs
at
30
‐
second
intervals
to
Panorama
(not
user
configurable).
Buffered
log
forwarding
is
very
valuable
when
the
firewall
loses
connectivity
to
Panorama.
The
firewall
buffers
log
entries
to
its
local
hard
disk
and
keeps
a
pointer
to
record
the
last
log
entry
that
was
sent
to
Panorama.
When
connectivity
is
restored
the
firewall
resumes
forwarding
logs
from
where
it
left
off.
The
disk
space
available
for
buffering
depends
on
the
log
storage
quota
for
the
platform
and
the
volume
of
logs
that
are
pending
roll
over.
If
the
firewall
was
disconnected
for
a
long
time
and
the
last
log
forwarded
was
rolled
over,
all
the
logs
from
its
local
hard
disk
will
be
forwarded
to
Panorama
on
reconnection.
If
the
available
space
on
the
local
hard
disk
of
the
firewall
is
consumed,
the
oldest
entries
are
deleted
to
allow
logging
of
new
events.
Live Mode Log Forwarding from
Device
This
option
is
enabled
when
the
check
box
for
Buffered Log Forwarding
from Device
is
cleared.
In
live
mode,
the
managed
firewall
sends
every
log
transaction
to
Panorama
at
the
same
time
as
it
records
it
on
the
firewall.
Logging
Options
Pertains
to
Description
Only Active Primary Logs to Local
Disk
Default:
Disabled
Panorama
virtual
appliance
that
is
logging
to
a
virtual
disk
and
is
set
up
in
a
high
availability
(HA)
configuration.
Allows
you
to
configure
only
the
Active
‐
Primary
Panorama
peer
to
save
logs
to
the
local
disk.