
112
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Enable
Log
Forwarding
to
Panorama
Manage
Log
Collection
Step
4
(Optional)
Schedule
log
exports
to
an
SCP
or
an
FTP
server.
If
you
plan
to
use
SCP,
after
pushing
the
template
you
must
log
in
to
each
managed
device,
open
the
scheduled
log
export,
and
click
the
Test SCP server
connection
button.
The
connection
is
not
established
until
the
firewall
accepts
the
host
key
for
the
SCP
server.
For
Traffic,
Threat,
URL
Filtering,
Data
Filtering,
HIP
Match,
and
WildFire
logs,
you
can
schedule
log
export
using
Panorama
templates.
1.
In
the
Device
tab,
select
a
Template
from
the
drop
‐
down.
2.
Select
Device > Scheduled Log Export
and
click
Add
.
3.
Enter
a
Name
for
the
scheduled
log
export
and
Enable
it.
4.
Select
the
Log Type
to
export.
To
schedule
exports
for
multiple
types,
you
must
schedule
a
log
export
for
each
type.
5.
Select
the
daily
Scheduled Export Start Time
.
The
options
are
in
15
‐
minute
increments
for
a
24
‐
hour
clock
(00:00
‐
23:59).
6.
Select
the
Protocol
to
export
the
logs:
SCP
(secure)
or
FTP
.
For
FTP,
you
have
the
option
to
Enable FTP Passive Mode
.
7.
Enter
the
Hostname
or
IP
address
of
the
server.
8.
Define
the
following
details
if
the
server
requires
them
for
the
firewall
to
connect:
a.
Enter
the
Port
number.
By
default,
FTP
uses
port
21
and
SCP
uses
port
22.
b.
Enter
the
Path
or
directory
in
which
to
save
the
exported
logs.
c.
Enter
the
Username
and
Password
(and
Confirm
Password
)
to
access
the
server.
9.
Click
OK
.
Step
5
Save
all
the
configuration
changes.
1.
Click
Commit
,
and
select
Panorama
as
the
Commit Type
to
save
the
changes
to
the
running
configuration
on
Panorama.
2.
Click
Commit
,
and
select
Template
as
the
Commit Type
to
push
the
changes
to
the
firewalls
included
in
the
selected
template.
3.
Click
Commit
,
and
select
Device Groups
as
the
Commit Type
to
push
the
changes
to
the
firewalls
included
in
the
selected
device
group.
Configure
Log
Forwarding
to
Panorama
(Continued)