Monitoring and Logging Flashcards
The VM-Series firewall on AWS can publish native PAN-OS metrics, which you can use to monitor the firewalls to what logging system?
AWS CloudWatch
What do the logs in AWS Cloud Watch allow admins to do?
assess performance and usage patterns that can be used to take action for launching or terminating instances of the VM-Series firewalls
The firewalls use AWS APIs to publish the metric to a?
namespace
What is a namespace in AWS (CloudWatch)?
location on AWS where the metrics are collected at a specified time interval
When you configure the firewalls to publish metrics to AWS CloudWatch, there are two namespaces where you can view metrics. What are they?
- primary namespace
- secondary namespace
What does the primary namespace do?
collects and aggregates the selected metric for all instances configured to use the namespace
What is the purpose of the secondary namespace?
allows to filter the metrics using the hostname and AWS instance ID metadata (or dimensions) and get visibility into the usage and performance of individual VM-Series firewalls
How is the secondary namespace created and with what suffix?
automatically with the suffix _dimensions
What needs to be done on the firewall to be able to send logs to CloudWatch?
go to Device > VM-Series and enable CloudWatch montoring, specify the namespace and update interval in minutes
What is the Update Interval
in the AWS CloudWatch configuration on a firewall?
frequency at which the firewall publishes the metrics to CloudWatch
What is the min and max interval for firewall to publish logs to CloudWatch?
min 1, max 60
What is the name of the service similar to AWS CloudWatch in Azure and GCP?
- Azure = Application Insights
- Google = Stackdriver
What do the published metrics in CloudWatch allow admins to do?
assess firewall performance and usage patterns so that you can set alarms and take action to automate events such as launching or terminating instances of the VM-Series firewalls
How are the metrics published to firewalls?
through content updates; make sure that you have the minimum content release version that is required to enable this capability on your VM-Series firewall
In terms of data plane utilization, what metrics are available for monitoring?
- Dataplane CPU Utilization (%)
- Dataplane Packet Buffer Utilization (%)