StudyToCert

All certifications / NGFW Engineer / Lessons

Palo Alto Networks Certified Next-Generation Firewall Engineer NGFW-Engineer · Domain 2: PAN-OS device setting configuration

Logging: log types, log forwarding profiles, syslog/SNMP/email/HTTP server profiles, Device > Log Settings, Strata Logging Service

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Logs are how you prove what the firewall did and how you feed a security operations center (SOC). PAN-OS writes many log types, visible under Monitor > Logs. The ones you will use most are Traffic (a record of each session, by default written at session end), Threat (vulnerability, spyware, virus, flood and scan detections), URL Filtering, WildFire Submissions, Data Filtering, HIP Match, GlobalProtect, User-ID, IP-Tag, Decryption, Tunnel Inspection, Authentication, Configuration, System and Alarms. The Unified log view combines several types for one search, and filters such as ( addr.src in 10.1.1.5 ) and ( action eq deny ) narrow results quickly.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study NGFW Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the NGFW Engineer study plan