A knowledge base article about Enabling and Disabling Logging of Denied Traffic. provided by the UC Berkeley IT Service Hub - Knowledge Portal
When troubleshooting issues with the firewalls including why connections were not allowed by a rule, it is sometimes necessary to enable logging of denied traffic. The steps necessary to configure logging of denied traffic are as follows:
At this point, any traffic that is stopped by the firewall, because their is not an allow rule, will be logged to the "Traffic" logs under the "Monitor" tab in Panorama. To undo this setting when you are done: