202
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Monitor
Panorama
Administer
Panorama
Monitor
Panorama
To
monitor
Panorama,
you
can
either
periodically
view
the
system
and
configuration
logs
on
Panorama
or
configure
SNMP
traps
and/or
alerts
that
notify
you
when
a
monitored
metric
changes
state
or
reaches
a
threshold
on
Panorama.
alerts
and
SNMP
traps
are
useful
for
immediate
notification
about
critical
system
events
that
require
your
attention.
Panorama
System
and
Configuration
Logs
You
can
configure
Panorama
to
send
notifications
if
a
system
event
occurs
or
any
time
a
configuration
change
is
made.
By
default,
Panorama
logs
every
configuration
change
to
the
configuration
log.
On
the
system
log,
each
event
has
a
severity
level
associated
with
it.
The
level
indicates
the
urgency
and
the
impact
of
the
event,
and
you
can
choose
to
record
all
or
selected
system
events,
depending
on
the
severity
levels
that
you
want
to
monitor.
Config
Logs
—Enable
forwarding
of
Configuration
logs
by
specifying
a
server
profile
in
the
log
settings
configuration
(
Panorama > Log Settings > Config Logs
).
System
Logs
—Enable
forwarding
of
System
logs
by
specifying
a
server
profile
in
the
log
settings
configuration
(
Panorama > Log Settings > System Logs
).
Select
a
server
profile
for
each
severity
level
you
want
to
forward.
The
following
table
summarizes
the
system
log
severity
levels:
The
M
‐
100
appliance
stores
configuration
and
system
logs
on
the
HDD.
The
Panorama
virtual
appliance
stores
the
logs
on
the
assigned
storage
volume.
If
you
need
longer
‐
term
storage
of
logs
for
auditing,
you
can
also
configure
Panorama
to
forward
the
logs
to
a
syslog
server.
This
section
covers
Panorama
logs
only.
For
information
on
forwarding
logs
from
the
managed
firewalls,
see
.
Severity
Description
Critical
Indicates
a
failure
and
signals
the
need
for
immediate
attention,
such
as
a
hardware
failure,
including
HA
failover
and
link
failures.
High
Serious
issues
that
will
impair
the
operation
of
the
system,
including
disconnection
of
a
Log
Collector
or
a
commit
failure.
Medium
Mid
‐
level
notifications,
such
as
antivirus
package
upgrades,
or
a
Collector
Group
commit.
Low
Minor
severity
notifications,
such
as
user
password
changes.
Informational
Notification
events
such
as
log
in/log
off,
any
configuration
change,
authentication
success
and
failure
notifications,
commit
success,
and
all
other
events
not
covered
by
the
other
severity
levels.