QuestionQ23

PAN-OS Networking Configuration

An administrator is using a Panorama template to configure firewalls to forward logs to a newly provisioned Strata Logging Service instance. The operational requirement is to preserve existing logging to on-premises Panorama log collectors for immediate, low-latency queries while also forwarding logs to Strata Logging Service for long-term archival. Cloud logging connectivity has already been configured and enabled.

Which additional action is required to fulfill the operational requirement?

  • A Enable duplicate logging (cloud and on-premises) under Device -> Setup -> Management in the appropriate templates.
  • B Enable log syncing and commit the template changes to both the on-premises and cloud collectors.
  • C In the collector group settings, add the Strata Logging Service as a secondary destination for the on-premises collector.
  • D Add the Panorama log collector and Strata Logging Service IP addresses to the cloud logging service routes to ensure dual-path cloud and on-premises reachability.
Explanation

For Panorama-managed firewalls, Enable Duplicate Logging (Cloud and On-Premise) causes the firewalls to save copies of their logs both to Strata Logging Service and to the existing Panorama or distributed Log Collector architecture. This preserves local, low-latency log access while sending the same log data to cloud storage.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!