Summary
In this chapter, you learned all about how logging works and how to scale and set up the infrastructure to capture logs. You also learned some methods to send logs out to Palo Alto Networks logging appliances or cloud instances. You learned how to set up forwarding to syslog servers and send out emails on certain events. Finally, you learned how to leverage filters to drill down into detailed information so that you can quickly find what you need in the ACC and how to manage the built-in reports and create custom ones.
If you’re studying for the PCNSE, take note of the different ways in which logs can be forwarded to external devices (panorama, CDL, syslog, and so on) and be able to identify the different types of logs (traffic, threat, system logs, and so on).
In the next chapter, we will be learning how to set up site-to-site and GlobalProtect VPN tunnels and how to create custom applications and threats.