<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Client Log Dump Format in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-log-dump-format/m-p/590945#M5524</link>
    <description>&lt;P&gt;There is so much data here that it can be hard to define in a single post.&amp;nbsp; What I would start with is the first number (P5200-T7744). These are the Process Identification Numbers (PID) of the service and threads that are running. The number after that (1916) is the command being sent.&lt;BR /&gt;&lt;BR /&gt;In the PanGPS file for example you can look up the command 25 to see newly started threads.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;(P16240-T48584)Debug( 25): 06/26/24 09:07:22:689 create thread 0x5dc720 with thread ID 45612&lt;BR /&gt;(P6668-T16780)Debug( 25): 06/28/24 14:06:22:680 create thread 0xb18 with thread ID 39684&lt;BR /&gt;&lt;BR /&gt;If you search for the ID then next line that contains the number it should give you an idea of what the thread is doing. Some threads will give the name of the process, but in the example of the gateway being checked it will not provide a name.&lt;BR /&gt;&lt;BR /&gt;(P16240-T45612)Debug( 449): 06/26/24 09:07:22:689 VpnProcMonitor thread starts&lt;/P&gt;
&lt;P&gt;(P6668-T39684)Debug(5717): 06/28/24 14:06:22:696 getaddrinfo host.GetString() xxx.gpcloudservice.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So searching for the string in the first parenthesis will provide you what occurred during the life cycle of the thread.&amp;nbsp; Be aware that some threads will remain active through out the logs and so some data will be missing due to log roll-over.&amp;nbsp; Hope that helps some.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2024 15:31:23 GMT</pubDate>
    <dc:creator>gshort</dc:creator>
    <dc:date>2024-07-02T15:31:23Z</dc:date>
    <item>
      <title>GlobalProtect Client Log Dump Format</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-log-dump-format/m-p/487692#M2780</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would like to parse and correlate multiple .log files from GP log dump.&lt;BR /&gt;&lt;BR /&gt;Example log from PanGPS.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;(P5200-T7744)Debug(1916): 05/16/22 12:47:28:106 Send response to client for request hip-ack │&lt;BR /&gt;(P5200-T7744)Dump (11923): 05/16/22 12:47:28:106 Set m_bPreviousSwitchOffMsg to 0&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Do you know what are the types/meaning of the fields?&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 06:52:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-log-dump-format/m-p/487692#M2780</guid>
      <dc:creator>Martin_Zichacek</dc:creator>
      <dc:date>2022-05-17T06:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Client Log Dump Format</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-log-dump-format/m-p/590945#M5524</link>
      <description>&lt;P&gt;There is so much data here that it can be hard to define in a single post.&amp;nbsp; What I would start with is the first number (P5200-T7744). These are the Process Identification Numbers (PID) of the service and threads that are running. The number after that (1916) is the command being sent.&lt;BR /&gt;&lt;BR /&gt;In the PanGPS file for example you can look up the command 25 to see newly started threads.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;(P16240-T48584)Debug( 25): 06/26/24 09:07:22:689 create thread 0x5dc720 with thread ID 45612&lt;BR /&gt;(P6668-T16780)Debug( 25): 06/28/24 14:06:22:680 create thread 0xb18 with thread ID 39684&lt;BR /&gt;&lt;BR /&gt;If you search for the ID then next line that contains the number it should give you an idea of what the thread is doing. Some threads will give the name of the process, but in the example of the gateway being checked it will not provide a name.&lt;BR /&gt;&lt;BR /&gt;(P16240-T45612)Debug( 449): 06/26/24 09:07:22:689 VpnProcMonitor thread starts&lt;/P&gt;
&lt;P&gt;(P6668-T39684)Debug(5717): 06/28/24 14:06:22:696 getaddrinfo host.GetString() xxx.gpcloudservice.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So searching for the string in the first parenthesis will provide you what occurred during the life cycle of the thread.&amp;nbsp; Be aware that some threads will remain active through out the logs and so some data will be missing due to log roll-over.&amp;nbsp; Hope that helps some.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 15:31:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-log-dump-format/m-p/590945#M5524</guid>
      <dc:creator>gshort</dc:creator>
      <dc:date>2024-07-02T15:31:23Z</dc:date>
    </item>
  </channel>
</rss>

