Configuring log forwarding profiles
The firewall will not automatically forward all logs to Panorama or Logging Service. Log forwarding needs to be configured and assigned to specific logs or log types before anything is sent out. Two main types of logs can be forwarded:
- System event logs: Any logs related to how the system is operating or events happening on the system itself
- Traffic flow-related logs: All logs related to packets flowing through the data plane of the firewall
Device daemon-related logs are only stored locally.
Important note
Only logs that are being stored locally can be forwarded. Any rule, policy, or profile that is set to not log cannot generate logs to be forwarded. Forwarded logs will also remain available locally (for as long as storage allows for the log to be retained); they are not purged after being forwarded.
In the firewall, you can check whether log forwarding is available and working with the following...