130
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Log
Collection
Deployments
Manage
Log
Collection
Figure:
Log
Forwarding
to
Panorama
and
then
to
External
Services
Forward
logs
from
firewalls
to
Panorama
and
to
external
services
in
parallel—In
this
configuration,
both
Panorama
and
the
external
services
are
endpoints
of
separate
log
forwarding
flows;
the
firewalls
do
not
rely
on
Panorama
to
forward
logs
to
external
services.
This
configuration
suits
deployments
in
which
the
connections
between
firewalls
and
external
services
have
sufficient
bandwidth
to
sustain
the
logging
rate.
(This
is
often
the
case
when
the
connections
are
local.)
To
forward
logs
from
firewalls
directly
to
external
services,
define
server
profiles
using
the
template
Device > Server Profiles
options.
describes
how
to
forward
logs
from
firewalls
to
Panorama
and
to
external
services
in
parallel.
Figure:
Log
Forwarding
to
External
Services
and
Panorama
in
Parallel
Forward
logs
from
firewalls
directly
to
external
services
and
also
from
Panorama
to
external
services—
This
configuration
is
a
hybrid
of
the
previous
two.
It
suits
deployments
that
require
sending
duplicate
Syslog
messages
to
multiple
Security
Information
and
Event
Management
(SIEM)
solutions,
each
with
its
own
message
format
(for
example,
Splunk
and
ArcSight).
(This
duplication
does
not
apply
to
SNMP
traps
or
notifications.)
For
this
configuration,
you
must
define
server
profiles
for:
–
Forwarding
logs
from
the
firewalls
directly
to
the
external
services—Use
the
template
Device > Server
Profiles
options.
–
Forwarding
logs
from
Panorama
to
the
external
services—Use
the
Panorama > Server Profiles
options.