©
Palo
Alto
Networks,
Inc.
Panorama
6.1
Administrator’s
Guide
•
137
Manage
Log
Collection
Log
Collection
Deployments
Deploy
Panorama
with
Default
Log
Collectors
The
following
figures
illustrate
Panorama
in
a
centralized
log
collection
deployment.
In
these
examples,
the
Panorama
management
server
comprises
two
M
‐
100
appliances
in
Panorama
mode,
configured
for
active/passive
high
availability
(HA).
The
firewalls
send
logs
to
the
default
(pre
‐
configured)
local
Log
Collector
on
each
Panorama
M
‐
100
appliance.
This
is
the
recommended
deployment
if
the
firewalls
generate
up
to
10,000
logs/second.
(For
details
on
deployment
options,
see
.)
Step
9
Configure
the
Collector
Group.
If
each
Collector
Group
will
have
one
Log
Collector,
repeat
this
step
for
each
Collector
Group
before
continuing.
If
you
will
assign
all
the
Log
Collectors
to
one
Collector
Group,
perform
this
step
only
once.
Use
the
web
interface
of
the
primary
Panorama
management
server
to
1.
Select
Panorama > Collector Groups
,
click
Add
,
and
enter
a
Name
for
the
Collector
Group.
2.
(
Optional
)
Select
the
Monitoring
tab
and
configure
the
settings
if
you
will
use
SNMP
to
monitor
Log
Collectors.
3.
Select
the
Device Log Forwarding
tab
and,
in
the
Collector
Group
Members
section,
assign
one
or
more
Log
Collectors.
4.
In
the
Log
Forwarding
Preferences
section,
assign
firewalls
according
to
the
number
of
Log
Collectors
in
this
Collector
Group:
•
Single—Assign
the
firewalls
that
will
forward
logs
to
that
Log
Collector,
as
illustrated
in
.
•
Multiple—Assign
each
firewall
to
both
Log
Collectors
for
redundancy.
When
you
configure
the
preferences,
make
Log
Collector
1
the
first
priority
for
half
the
firewalls
and
make
Log
Collector
2
the
first
priority
for
the
other
half,
as
illustrated
in
.
5.
Click
OK
and
Commit
,
set
the
Commit Type
to
Panorama
,
and
click
OK
.
6.
Click
Commit
,
set
the
Commit Type
to
Collector Group
,
select
the
Collector
Groups
you
added,
and
click
OK
.
7.
Select
Panorama > Managed Collectors
to
verify
that
the
Log
Collector
configuration
is
synchronized
with
Panorama.
The
Configuration
Status
column
should
display
In
Sync
and
the
Run
Time
Status
column
should
display
connected.
Step
10
Configure
log
forwarding.
Use
the
web
interface
of
the
primary
Panorama
management
server
peer
to:
1.
2.
.
3.
(
Optional
)
Deploy
Panorama
with
Dedicated
Log
Collectors
(Continued)