<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interpreting debug log-receiver statistics command output in Log Forwarding Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/433798#M36</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Num cumulative drop entries in trsum, total number of "drop" logs in the traffic summary log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Enqueue Count, logs received to be forwarded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Send Count, logs forwarded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Netflow incoming count, received netflow logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What "size" firewall do you have, the log volume may be reaching the maximum rate the chassis/vm supports causing management slowness&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 14:38:14 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-09-14T14:38:14Z</dc:date>
    <item>
      <title>Interpreting debug log-receiver statistics command output</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/433724#M35</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having issue with management plane CPU going high. Upon checking we had identified the Logrcvr process is consuming more memory during the issue time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having syslog forwarding profile and Net flow profile configured on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had run the command&amp;nbsp;debug log-receiver statistics and got the below output. Can any please help me out on what the following parameters in the output means :&amp;nbsp;Num cumulative drop entries in trsum,&amp;nbsp;Enqueue Count,&amp;nbsp;Send Count,&amp;nbsp;Netflow incoming count&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log Output:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Logging statistics&lt;BR /&gt;------------------------------ -----------&lt;BR /&gt;Log incoming rate: 1657/sec&lt;BR /&gt;Log written rate: 1657/sec&lt;BR /&gt;Corrupted packets: 0&lt;BR /&gt;Corrupted URL packets: 0&lt;BR /&gt;Corrupted HTTP HDR packets: 0&lt;BR /&gt;Corrupted HTTP HDR Insert packets: 0&lt;BR /&gt;Corrupted EMAIL HDR packets: 0&lt;BR /&gt;Logs discarded (queue full): 0&lt;BR /&gt;Traffic logs written: 3891600225&lt;BR /&gt;GTP logs written: 0&lt;BR /&gt;Tunnel logs written: 0&lt;BR /&gt;Auth logs written: 0&lt;BR /&gt;Userid logs written: 19069&lt;BR /&gt;SCTP logs written: 0&lt;BR /&gt;GlobalProtect logs written: 182511&lt;BR /&gt;DECRYPTION logs written: 11886&lt;BR /&gt;URL logs written: 0&lt;BR /&gt;Wildfire logs written: 96605&lt;BR /&gt;Anti-virus logs written: 199&lt;BR /&gt;Maching Learning-virus logs written: 0&lt;BR /&gt;&amp;#27;[7mlines 1-23&amp;#27;[27m&amp;#27;[K &amp;#27;[KWildfire Anti-virus logs written: 1768&lt;BR /&gt;Spyware logs written: 49341679&lt;BR /&gt;Spyware-DNS logs written: 20973&lt;BR /&gt;Attack logs written: 0&lt;BR /&gt;Vulnerability logs written: 46438318&lt;BR /&gt;Data logs written: 0&lt;BR /&gt;Wif logs written: 0&lt;BR /&gt;Fileext logs written: 0&lt;BR /&gt;Fileext logs URL not written: 0&lt;BR /&gt;Fileext logs URL not written (timedout): 0&lt;BR /&gt;URL cache age out count: 0&lt;BR /&gt;URL cache full count: 0&lt;BR /&gt;URL cache key exist count: 0&lt;BR /&gt;URL cache wrt incomplete http hdrs count: 0&lt;BR /&gt;URL cache rcv http hdr before url count: 0&lt;BR /&gt;URL cache full drop count(url log not received): 0&lt;BR /&gt;URL cache age out drop count(url log not received): 0&lt;BR /&gt;Email hdr cache count: 1695&lt;BR /&gt;Email hdr cache hit count: 1970&lt;BR /&gt;HTTP hdr insertion received: 0&lt;BR /&gt;HTTP hdr insertion processed: 0&lt;BR /&gt;HTTP hdr insert no URL drop count: 0&lt;BR /&gt;HTTP hdr insert with invalid URL log: 0&lt;BR /&gt;&amp;#27;[7mlines 24-46&amp;#27;[27m&amp;#27;[K &amp;#27;[KHTTP hdr insert with values exceeded max allowed length: 0&lt;BR /&gt;Traffic alarms dropped due to sysd write failures: 0&lt;BR /&gt;Traffic alarms dropped due to global rate limiting: 0&lt;BR /&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;BR /&gt;Traffic alarms generated count: 0&lt;BR /&gt;Netflow incoming count: 4053054063&lt;BR /&gt;Log Forward count: 14315436&lt;BR /&gt;Log Forward discarded (queue full) count: 0&lt;BR /&gt;Log Forward discarded (send error) count: 0&lt;BR /&gt;Total logs not written due to disk unavailability: 0&lt;BR /&gt;Logs not written since disk became unavailable: 0&lt;BR /&gt;DPI logs received: 0&lt;BR /&gt;HIP Report logs received: 0&lt;/P&gt;&lt;P&gt;Summary Statistics:&lt;BR /&gt;Num current entries in trsum:283974&lt;BR /&gt;Num cumulative entries in trsum:2399889465&lt;BR /&gt;Num current entries in thsum:282&lt;BR /&gt;Num cumulative entries in thsum:98934187&lt;BR /&gt;Num current entries in urlsum:0&lt;BR /&gt;Num cumulative entries in urlsum:0&lt;BR /&gt;Num current entries in gtpsum:0&lt;BR /&gt;Num cumulative entries in gtpsum:0&lt;BR /&gt;&amp;#27;[7mlines 47-69&amp;#27;[27m&amp;#27;[K &amp;#27;[KNum current entries in sctpsum:0&lt;BR /&gt;Num cumulative entries in sctpsum:0&lt;BR /&gt;Num current drop entries in trsum:0&lt;BR /&gt;Num cumulative drop entries in trsum:5273142&lt;BR /&gt;Num current drop entries in thsum:0&lt;BR /&gt;Num cumulative drop entries in thsum:0&lt;BR /&gt;Num current drop entries in urlsum:0&lt;BR /&gt;Num cumulative drop entries in urlsum:0&lt;BR /&gt;Num current drop entries in gtpsum:0&lt;BR /&gt;Num cumulative drop entries in gtpsum:0&lt;BR /&gt;Num current drop entries in sctpsum:0&lt;BR /&gt;Num cumulative drop entries in sctpsum:0&lt;BR /&gt;Num current drop entries in desum:0&lt;BR /&gt;Num cumulative drop entries in desum:0&lt;/P&gt;&lt;P&gt;External Forwarding stats:&lt;BR /&gt;Type&amp;nbsp; &amp;nbsp;Enqueue Count&amp;nbsp; &amp;nbsp;Send Count&amp;nbsp; &amp;nbsp; Drop&amp;nbsp; &amp;nbsp;Count Queue Depth&amp;nbsp; &amp;nbsp; Send &amp;#8;Rate(last 1min)&lt;BR /&gt;syslog 1626503687&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1626503687&amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;25922&lt;BR /&gt;snmp 0 0 0 0 &amp;#8; 0&lt;BR /&gt;email 0 0 0 0 &amp;#8;&amp;#27;[7mlines 70-89&amp;#27;[27m&amp;#27;[K &amp;#27;[K 0&lt;BR /&gt;raw 0 0 0 0 &amp;#8; 0&lt;BR /&gt;http 0 0 0 0 &amp;#8; 0&lt;BR /&gt;autotag 0 0 0 0 &amp;#8; 0&lt;BR /&gt;quarantine 0 0 0 0 &amp;#8; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-MESSAGE title="Re: Log forwarding - Local on Gateway or Panorama" uid="228994" url="https://live.paloaltonetworks.com/t5/general-topics/log-forwarding-local-on-gateway-or-panorama/m-p/228994#U228994" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-forum-thread lia-fa-icon lia-fa-forum lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 08:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/433724#M35</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-09-14T08:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting debug log-receiver statistics command output</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/433798#M36</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Num cumulative drop entries in trsum, total number of "drop" logs in the traffic summary log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Enqueue Count, logs received to be forwarded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Send Count, logs forwarded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Netflow incoming count, received netflow logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What "size" firewall do you have, the log volume may be reaching the maximum rate the chassis/vm supports causing management slowness&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 14:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/433798#M36</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-09-14T14:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting debug log-receiver statistics command output</title>
      <link>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/434184#M37</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having PA-850 firewall and the management plane is reaching till 80%.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon checking the process running the firewall during the issue period the Logrcvr process is consuming more virtual memory. We are having syslog forwarding for every security rule and also have Netflow configured for two interfaces on the firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also checked the Logrcvr log file and could see the traffic and threat logs being flushed constanly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just need to know what are the activities handled by the logrcvr process to minimize the load on the firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;#27;[7m PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND&amp;nbsp;&lt;BR /&gt;&amp;#27;(B&amp;#27;[m&amp;#27;[1m 4344 root 20 0 77100 9268 6864 R 100.0 0.2 190806:36 pan_task&lt;/P&gt;&lt;P&gt;&amp;#27;(B&amp;#27;[m&amp;#27;[1m 4345 root 20 0 77100 10320 7004 R 100.0 0.3 190812:41 pan_task&amp;nbsp;&lt;BR /&gt;&amp;#27;(B&amp;#27;[m&amp;#27;[1m 4346 root 20 0 72832 9340 6976 R 100.0 0.2 190822:03 pan_task&amp;nbsp;&lt;BR /&gt;&amp;#27;(B&amp;#27;[m&amp;#27;[1m 4347 root 20 0 76764 9636 7040 R 100.0 0.2 190814:29 pan_task&amp;nbsp;&lt;BR /&gt;&amp;#27;(B&amp;#27;[m&amp;#27;[1m 4343 root 20 0 102056 26028 6928 R 100.0 0.6 190813:41 pan_task&amp;nbsp;&lt;BR /&gt;&amp;#27;(B&amp;#27;[m 6207 root 20 0 2342984 285388 8992 S 50.0 6.9 17861:20 logrcvr&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 13:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/log-forwarding-discussions/interpreting-debug-log-receiver-statistics-command-output/m-p/434184#M37</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-09-15T13:37:25Z</dc:date>
    </item>
  </channel>
</rss>

