Can someone explain the difference to me?
Specifically, I have firewalls, panorama, panorama loggers and a syslog server. I just added the loggers but they don't seem to be forwarding to the syslog server. I'm trying to understand what feeds what and how that is configured.
Ultimately, DNS was the issue.
Figure one is what I'm hoping to achieve:
https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/panorama-overview/centralized-logging-and-reporting/log-forwarding-options.html
normally your firewalls will forward logs directly to panorama, and panorama can forward logs further along to a syslog server. in this configuration, the log collectors are a separate entity, so they're not part of "panorama". this means they need to be configured through the collector group "collector log forwarding" to forward logs to a syslog (remote connection vs local to panorama).