Configuring log collectors and log collector groups
To ensure that logs can be stored for an extended period of time, as you may need to comply with certain standards that require lengthy log storage (regulations such as SOX and HIPAA and standards such as ISO 27001 require several years’ worth of logs to be stored), logs can be exported into a dedicated log management system (tools like Elastic Stack, LogRhythm, or Splunk).
You can create additional log collectors by setting up and licensing a second Panorama in Panorama mode and creating a High Availability cluster, or by adding additional Panorama appliances and configuring them in logger mode. Both VM (Virtual Machine) and physical ‘M’ appliances can be used to achieve the aforementioned, but the cluster option requires both devices to be the same favor (both physical or both VMs)
You can do so from the CLI of the device you want to set to logger mode by executing the following command:
> request...