Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is troubleshooting an issue where logs from a Palo Alto Networks firewall are not being received by a configured syslog server. The firewall is sending other logs (e.g., traffic logs) successfully to Panorama, but specifically, threat logs are not appearing on the syslog server. The syslog server is reachable from the firewall, and a packet capture on the firewall's egress interface shows no UDP 514 traffic destined for the syslog server when a threat event occurs. Which configuration element is most likely misconfigured on the firewall?

  1. AThe Log Forwarding Profile for the threat logs.
  2. BThe Security policy rule allowing syslog traffic.
  3. CThe syslog server's IP address in the Server Profile.
  4. DThe firewall's system log settings.
Show answer & explanation

Correct answer: A. The Log Forwarding Profile for the threat logs.

If the firewall is not even sending the threat log traffic (confirmed by packet capture), the issue lies before the network transmission. The Log Forwarding Profile is where specific log types (like threat logs) are configured to be sent to external destinations (like a syslog server). If the threat log type is not included or incorrectly configured in the relevant Log Forwarding Profile, it won't be sent.

Why the other options are wrong

  • B. A Security policy rule would block traffic if it were being sent. The packet capture indicates no traffic is being sent at all, so the issue is prior to policy enforcement.
  • C. If the syslog server's IP address in the Server Profile was incorrect, other logs also wouldn't be sent, or the packet capture would show traffic to the wrong IP, which is not the case here.
  • D. The firewall's system log settings govern what system events are logged locally, not how threat logs are forwarded to external servers.

Log Forwarding Profile

A Palo Alto Networks configuration object that specifies which types of logs (e.g., traffic, threat, system) should be sent to which external log receivers (e.g., syslog, SNMP, HTTP).

  • Applied to Security policy rules or specific log types.
  • Determines the destination and format for forwarded logs.
  • Crucial for external log integration.

Memory trick: Forwarding profiles direct the logs' journey.

More Troubleshoot questions