Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard

A network administrator observes that logs from a Palo Alto Networks firewall are not being forwarded to the configured syslog server. The syslog server can be successfully pinged from the firewall's management interface, and a 'show logging-status' command on the firewall shows the syslog server as 'Connected' but '0' events forwarded. There are recent entries in the firewall's traffic and threat logs. What is the MOST likely reason for this issue?

  1. AThe syslog server is not configured to listen on the correct UDP port (514).
  2. BThe syslog server profile on the firewall has an incorrect source interface configured.
  3. CThe firewall's logging profile is not attached to the relevant security policies.
  4. DThe firewall's data plane is overloaded, preventing log forwarding.
Show answer & explanation

Correct answer: C. The firewall's logging profile is not attached to the relevant security policies.

The key here is that the firewall shows the syslog server as 'Connected' and there are logs present on the firewall, but '0' events are being forwarded. This indicates that the firewall can reach the syslog server and its log forwarding process is operational, but it hasn't been instructed to *send* specific logs. This instruction comes from attaching a logging profile (which points to the syslog server profile) to the relevant security policies where log generation is desired.

Why the other options are wrong

  • A. If the syslog server wasn't listening on the correct port, the firewall would likely report a connection issue or a different error, not 'Connected' with 0 events forwarded.
  • B. An incorrect source interface would likely prevent the 'Connected' status or cause a connectivity issue, as the firewall wouldn't be able to establish the connection or send packets from the wrong interface.
  • D. While a data plane overload can affect performance, it's less likely to show 'Connected' but '0' events forwarded if logs are actively being generated and stored locally. Resource issues usually manifest as dropped packets or general slowness, not a complete lack of forwarding despite a 'Connected' status.

Log Forwarding Configuration

For Palo Alto Networks firewalls to forward logs to external syslog servers, a logging profile must be created, configured to send logs to a syslog server profile, and then attached to the relevant security policies.

  • Logging profile links policies to syslog server.
  • Syslog server profile defines server details (IP, port, protocol).
  • Without attachment, logs remain local (or are not generated).

Memory trick: Syslog needs a 'Profile Pointer' to send the 'Paper'.

More Troubleshoot questions