NGFW-ENGINEER · Question #108
A firewall administrator uses Panorama to manage a fleet of firewalls. After successfully onboarding the firewalls to Strata Logging Service and enabling cloud logging via a template, the security…
The correct answer is B. Duplicate logging (cloud and on-premises) is disabled under Device --> Setup --> Management. When cloud logging is enabled, logs are sent exclusively to Strata Logging Service unless duplicate logging is explicitly enabled. If duplicate logging is not enabled under Device → Setup → Management in the Panorama template, logs will no longer be forwarded to on-premises…
Question
A firewall administrator uses Panorama to manage a fleet of firewalls. After successfully onboarding the firewalls to Strata Logging Service and enabling cloud logging via a template, the security operations team reports that they can no longer see new logs on the on-premises Panorama log collectors. Logs are appearing correctly in Strata Logging Service. Which setting was likely missed in the Panorama template configuration?
Options
- AThe device certificates for the Panorama log collectors were not renewed after enabling the cloud
- BDuplicate logging (cloud and on-premises) is disabled under Device --> Setup --> Management.
- CThe Log Forwarding profile was modified to send logs only to the Strata Logging Service and no
- DThe Panorama log collectors were not defined as primary destinations within the collector group
How the community answered
(45 responses)- A2% (1)
- B91% (41)
- C2% (1)
- D4% (2)
Explanation
When cloud logging is enabled, logs are sent exclusively to Strata Logging Service unless duplicate logging is explicitly enabled. If duplicate logging is not enabled under Device → Setup → Management in the Panorama template, logs will no longer be forwarded to on-premises Panorama log collectors even though they appear correctly in Strata Logging Service.
Topics
Community Discussion
No community discussion yet for this question.