Logging, Monitoring, Panorama & Automation
Palo Alto NGFW — PCNSE track EVE-NG — PAN-OS VM (GUI + CLI)
مقصدObjectiveObjective
مانیٹرنگ کے لیے اے سی سی اور لاگ ویوز استعمال کرنا، لاگ فارورڈنگ کنفیگر کرنا، اور پینوراما ٹیمپلیٹس، ڈیوائس گروپس اور اے پی آئی آٹومیشن سمجھنا۔Monitoring ke liye ACC aur log views use karna, log forwarding configure karna, aur Panorama templates, device groups aur API automation samajhna.Use ACC and log views for monitoring, configure log forwarding, and understand Panorama templates, device groups, and API automation.
آسان مثالSimple AnalogySimple Analogy
لاگز فائر وال کی ڈائری ہیں۔ اے سی سی ہائی لائٹ ریل ہے — ٹاپ ایپلی کیشنز، ٹاپ تھریٹس، ٹاپ یوزرز ایک نظر میں۔ پینوراما ہیڈ آفس ہے جو ایک پالیسی لکھتا ہے اور ہر برانچ کو پش کرتا ہے۔Logs firewall ki diary hain. ACC highlight reel hai — top applications, top threats, top users ek nazar mein. Panorama head office hai jo ek policy likhta hai aur har branch ko push karta hai.Logs are the firewall's diary. ACC is the highlight reel — top applications, top threats, top users at a glance. Panorama is the head office that writes one policy and pushes it to every branch.
سیٹ اپLab SetupLab Setup
ٹریفک کے ساتھ چلتا ہوا پالو-03 بلڈ استعمال کریں۔ پینوراما کنسیپٹس کے لیے جی یو آئی ہائرارکی ریویو کریں — اس لیب میں پینوراما وی ایم آپشنل ہے۔Traffic ke saath chalta hua palo-03 build use karein. Panorama concepts ke liye GUI hierarchy review karein — is lab mein Panorama VM optional hai.Use the running palo-03 build with traffic flowing. For Panorama concepts, review the GUI hierarchy — a Panorama VM is optional in this lab.
اقداماتStepsSteps
Step 1
ٹریفک لاگ اور اے سی سی سے اسٹارٹ کریں۔ کسی بھی ٹرابل شوٹنگ سے پہلے دیکھیں فائر وال نے اصل میں کیا دیکھا — اندازے ایویڈنس کے بعد۔Traffic log aur ACC se start karein. Kisi bhi troubleshooting se pehle dekhein firewall ne asal mein kya dekha — andazay evidence ke baad.Start with the traffic log and ACC. Before any troubleshooting, look at what the firewall actually saw — guesses come after evidence.
show log traffic direction equal backward
🖱️ مانیٹر > لاگز > ٹریفک: رول نیم، ایپلی کیشن یا ایکشن سے فلٹر کریں؛ ٹاپ ٹاکرز کے لیے اے سی سی ٹیب چیک کریں۔Monitor > Logs > Traffic: rule name, application ya action se filter karein; top talkers ke liye ACC tab check karein.Monitor > Logs > Traffic: filter by rule name, application, or action; check the ACC tab for top talkers.
Step 2
سس لاگ سرور کی طرف لاگ فارورڈنگ پروفائل بنائیں — اسی طرح لاگز ایس او سی کے ایس آئی ای ایم تک پہنچتے ہیں۔ اسے اہم رولز سے اٹیچ کریں۔Syslog server ki taraf log forwarding profile banayein — isi tarah logs SOC ke SIEM tak pohonchte hain. Ise important rules se attach karein.Create a log forwarding profile toward a syslog server — this is how logs reach the SOC's SIEM. Attach it to rules that matter.
set shared log-settings profiles SIEM-Forward match-list Traffic-All actions-for-traffic-logs forwarding syslog-profile Syslog-Server commit
🖱️ آبجیکٹس > لاگ فارورڈنگ: ’ایس آئی ای ایم فارورڈ‘ پروفائل بنائیں جو ڈیوائس > سرور پروفائلز > سس لاگ کے نیچے سس لاگ سرور پروفائل کی طرف پوائنٹ کرے۔Objects > Log Forwarding: 'SIEM-Forward' profile banayein jo Device > Server Profiles > Syslog ke neeche syslog server profile ki taraf point kare.Objects > Log Forwarding: create profile 'SIEM-Forward' pointing to a syslog server profile under Device > Server Profiles > Syslog.
Step 3
پینوراما ماڈل سیکھیں: ٹیمپلیٹس = فائر والز میں شیئرڈ ڈیوائس/نیٹ ورک سیٹنگز؛ ڈیوائس گروپس = لوکل اوور رائڈز کے ساتھ شیئرڈ پالیسیز۔ ایک دفعہ کمیٹ، سب کو پش۔Panorama model seekhein: templates = firewalls mein shared device/network settings; device groups = local overrides ke saath shared policies. Ek dafa commit, sab ko push.Learn the Panorama model: templates = device/network settings shared across firewalls; device groups = shared policies with local overrides. Commit once, push to all.
debug log-receiver statistics
🖱️ پینوراما > سیٹ اپ (کنسیپٹ): ٹیمپلیٹس انٹرفیسز/روٹس اٹھاتے ہیں، ڈیوائس گروپس پالیسیز اٹھاتے ہیں — ایک چینج، ہر جگہ پش۔Panorama > Setup (concept): templates interfaces/routes uthate hain, device groups policies uthate hain — ek change, har jagah push.Panorama > Setup (concept): templates carry interfaces/routes, device groups carry policies — one change, pushed everywhere.
Step 4
آٹومیشن کنسیپٹ: پی اے این او ایس ایکس ایم ایل اے پی آئی اسکرپٹس کو اسٹیٹس پُل اور کنفگ پش کرنے دیتا ہے۔ اوپر ریل ایگزامپل — پروڈکشن میں پین او ایس پائتھون ایس ڈی کے اور اے پی آئی کیز استعمال کریں، اسکرپٹس میں پاس ورڈز کبھی نہیں۔Automation concept: PAN-OS XML API scripts ko status pull aur config push karne deta hai. Upar real example — production mein pan-os-python SDK aur API keys use karein, scripts mein passwords kabhi nahi.Automation concept: the PAN-OS XML API lets scripts pull status and push config. Real example above — in production use the pan-os-python SDK and API keys, never passwords in scripts.
curl -k "https://<fw-ip>/api/?type=op&cmd=<show><system><info></info></system></show>&key=<api-key>"
Step 5
ٹرابل شوٹنگ ورک فلو: پہلے اے سی سی/لاگ فلٹرز، پھر اسٹک کمیٹس کے لیے ’شو جابز آل‘، پھر سسٹم لاگز۔ ہمیشہ چینجز سے پہلے ایویڈنس۔Troubleshooting workflow: pehle ACC/log filters, phir stuck commits ke liye 'show jobs all', phir system logs. Hamesha changes se pehle evidence.Troubleshooting workflow: ACC/log filters first, then 'show jobs all' for stuck commits, then system logs. Evidence before changes, always.
show jobs all
🖱️ مانیٹر > لاگز > سسٹم + ڈیوائس > ٹرابل شوٹنگ: کنفگ خراب ہو تو کمیٹ جابز اور سسٹم لاگز چیک کریں۔Monitor > Logs > System + Device > Troubleshooting: config kharab ho to commit jobs aur system logs check karein.Monitor > Logs > System + Device > Troubleshooting: check commit jobs and system logs when config misbehaves.
تصدیقVerifyVerify
ٹریفک اے سی سی میں صحیح ایپس کے ساتھ نظر آتا ہے، لاگز سس لاگ کو فارورڈ ہوتے ہیں، اور آپ پینوراما ٹیمپلیٹ/ڈیوائس گروپ ہائرارکی کاغذ پر بنا سکتے ہیں۔Traffic ACC mein sahi apps ke saath nazar aata hai, logs syslog ko forward hote hain, aur aap Panorama template/device-group hierarchy kagaz par bana sakte hain.Traffic appears in ACC with correct apps, logs forward to syslog, and you can sketch the Panorama template/device-group hierarchy on paper.
show log traffic direction equal backward debug log-receiver statistics
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ سس لاگ سرور پر کوئی لاگز نہیں آ رہے۔Syslog server par koi logs nahi aa rahe.No logs arriving at the syslog server.
✅ سس لاگ سرور پروفائل کا آئی پی/پورٹ ویریفائی کریں، کنفرم کریں لاگ فارورڈنگ پروفائل رولز سے اٹیچ ہے، اور چیک کریں فائر وال سرور تک پہنچ سکتا ہے (پنگ/ٹیسٹ)۔ یہ بھی کنفرم کریں کہ لاگ سیویرٹی فلٹرز سب کچھ ایکسکلوڈ نہیں کر رہے۔Syslog server profile ka IP/port verify karein, confirm karein log forwarding profile rules se attach hai, aur check karein firewall server tak pohonch sakta hai (ping/test). Ye bhi confirm karein ke log severity filters sab kuch exclude nahi kar rahe.Verify the syslog server profile IP/port, confirm the log forwarding profile is attached to the rules, and check the firewall can reach the server (ping/test). Also confirm log severity filters aren't excluding everything.
⚠️ پینوراما پش میں ایک فائر وال پر کمیٹ فیلیئر شو ہو رہا ہے۔Panorama push mein ek firewall par commit failure show ho raha hai.Panorama push shows a commit failure on one firewall.
✅ ایگزیکٹ ایرر کے لیے جاب ڈیٹیلز پڑھیں — عام طور پر ٹیمپلیٹ ویری ایبل یا انٹرفیس نیم جو اس ڈیوائس پر موجود نہیں۔ ٹیمپلیٹ/اسٹیک اسائنمنٹ ٹھیک کریں، پھر دوبارہ پش کریں۔Exact error ke liye job details parhein — aam tor par template variable ya interface name jo us device par maujood nahi. Template/stack assignment theek karein, phir dobara push karein.Read the job details for the exact error — usually a template variable or interface name that doesn't exist on that device. Fix the template/stack assignment, then re-push.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ لاگز فائر وال سے ایس آئی ای ایم تک کیسے پہنچتے ہیں؟Logs firewall se SIEM tak kaise pohonchte hain?How do logs get from the firewall to a SIEM?
لاگ فارورڈنگ سلیکٹڈ لاگز کو ایکسٹرنل کلیکٹرز (سس لاگ/ایس آئی ای ایم) بھیجتی ہے۔ فائر وال پر آپ آبجیکٹس کے نیچے لاگ فارورڈنگ پروفائل ڈیفائن کرتے ہیں اور اسے رولز سے اٹیچ کرتے ہیں، بلٹ اِن لاگ سیٹنگز کے ساتھ۔Log forwarding selected logs ko external collectors (syslog/SIEM) bhejta hai. Firewall par aap Objects ke neeche log forwarding profile define karte hain aur ise rules se attach karte hain, built-in log settings ke saath.Log forwarding sends selected logs to external collectors (syslog/SIEM). On the firewall you define a log forwarding profile under Objects and attach it to rules, alongside the built-in log settings.
❓ Panorama کیا ہے اور یہ کیا centralize کرتا ہے؟Panorama kya hai aur yeh kya centralize karta hai?What is Panorama and what does it centralize?
پینوراما سینٹرل مینیجر ہے: ٹیمپلیٹس نیٹ ورک/ڈیوائس کنفگ پش کرتے ہیں، ڈیوائس گروپس پالیسیز پش کرتے ہیں، اور آپ ایکس ایم ایل اے پی آئی یا پی اے این او ایس ایس ڈی کے سے آٹومیٹ کر سکتے ہیں — سیم کمیٹس، اسکیل پر۔Panorama central manager hai: templates network/device config push karte hain, device groups policies push karte hain, aur aap XML API ya PAN-OS SDK se automate kar sakte hain — same commits, scale par.Panorama is the central manager: templates push network/device config, device groups push policies, and you can automate via the XML API or PAN-OS SDK — same commits, at scale.