A security operations center (SOC) uses Panorama to monitor all firewalls. They notice that some log entries show a severity of 'critical' but the alerting system does not fire. The log forwarding profile on Panorama is configured to send syslog alerts for severity 'critical'. The syslog server receives other logs from Panorama but not these critical logs. The administrator checks the Panorama configuration and finds that the log forwarding profile is applied to the correct log types. What is the most likely issue?
Panorama only forwards logs it receives from managed firewalls. If critical logs are generated locally on a firewall and never sent to Panorama, Panorama's log forwarding profile cannot forward them, explaining why the syslog server receives other logs but not these.
Why this answer
The most likely issue is that the critical logs are generated on the firewall but not forwarded to Panorama. Panorama can only forward logs it has received from its managed firewalls; if the firewall’s log forwarding or logging settings (e.g., log severity threshold, log buffering, or connectivity to the Log Collector) prevent those critical logs from reaching Panorama, then Panorama’s syslog forwarding profile will never see them. The fact that other logs arrive at the syslog server indicates Panorama’s forwarding works, so the gap must be upstream at the firewall-to-Panorama log collection stage.
Exam trap
The trap here is that candidates assume Panorama’s log forwarding profile is the only configuration needed, overlooking that logs must first be collected from the firewall via the Log Collector, and that the firewall’s own logging settings or connectivity can prevent critical logs from reaching Panorama.
How to eliminate wrong answers
Option A is wrong because the log forwarding profile on Panorama is applied to the correct log types and the syslog server receives other logs, proving the profile is active; the issue is not about the profile being applied to firewalls but about logs not reaching Panorama. Option C is wrong because if the Log Collector were not processing logs correctly, other logs would also be missing or corrupted, but the syslog server receives other logs from Panorama, indicating the collector is functioning. Option D is wrong because the syslog server receives other logs from Panorama, so it is not filtering based on source IP; the problem is that the critical logs never leave Panorama, not that they are dropped by the syslog server.