<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Status Red for log-collector-es-cluster health in M600 in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/455045#M597</link>
    <description>&lt;P&gt;Good to know. I had to upgrade the Passive Panorama during the working hours to get the management's green light for upgrading the active panorama and LCs during the night, so the active Panorama upgrade started after 8 hours from the completion of the passive Panorama. However in my case, on one the log collectors the ES cluster was struggling to come up (the output for command&amp;nbsp;&lt;SPAN&gt;show log-collector-es-cluster health was empty or sometimes later cli was hanging or even one time crashed), at the end it took about 2 hours seeing the ES cluster to come up on that LC (show log-collector-es-cluster health worked fine for the first time and showed the expected outputs) and also at this time the FW logs started coming into Panorama. For my case all FWs immediately after the upgrades got connections to LC according to "show logging-status device xxx. TAC is saying the status of ES Cluster should change to green after having "active_shards_percent_as_number" at 100%. I guess I have to wait another 10 hours for this.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 17:24:10 GMT</pubDate>
    <dc:creator>Mostafavi_DWR</dc:creator>
    <dc:date>2021-12-22T17:24:10Z</dc:date>
    <item>
      <title>Status Red for log-collector-es-cluster health in M600</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/454886#M591</link>
      <description>&lt;P&gt;After upgrading to 9.1.12-h3 from 9.1.8 the ElasticSearch cluster changed to Red on one the M600 log collectors and to no status shown for the other M600 collector and the logs stopped coming into Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 07:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/454886#M591</guid>
      <dc:creator>Mostafavi_DWR</dc:creator>
      <dc:date>2021-12-22T07:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Status Red for log-collector-es-cluster health in M600</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/454909#M592</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162441"&gt;@Mostafavi_DWR&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In PAN-OS 9.1.12 there is no known issue for ElasticSearch. When status is red, there is not much you can do. I would give log collector reboot. If the issue continues after reboot, I would generate tech-support file and open ticket.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the second issue, do you mean that log collectors are not showing status under: Panorama &amp;gt; Managed Collectors? As a next thing, I would check logs on log collector:&amp;nbsp;&lt;STRONG&gt;tail lines 200 mp-log ms.log &lt;/STRONG&gt;to see it can give more information. After upgrade the log collector should try to connect to Panorama on&amp;nbsp;&lt;SPAN&gt;TCP:&amp;nbsp;3978. If on Panorama status is showing properly either something is preventing to connect or log collector is not initiating connection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 09:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/454909#M592</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-22T09:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Status Red for log-collector-es-cluster health in M600</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/454999#M596</link>
      <description>&lt;P&gt;If the OP's situation and issue are like mine, the Panoramas (Primary-Active and Secondary/Passive) are in Panorama-mode -- meaning they function as Management and Log Collectors in what might be the only Collector Group.&amp;nbsp; Whenever we upgrade the Panoramas -- we have a pair of M-600s, the ES cluster is red for 6-24 hrs...&amp;nbsp; &amp;nbsp;I think (and need to test this) the best method to avoid this is to stop the LCs on the Panoramas from taking in logs from the managed FWs just seconds before you begin the upgrade on the Secondary PAN -- the ES cluster appears to go red after the upgrade because the ES database on each PAN's LC is out of sync (for lack of a better word).&amp;nbsp; If there is a way to disconnect the Managed Firewalls connections to the LCs, that is likely best overall -- they'll sit and queue locally on the FWs until they can connect to the LCs and forward them on.&amp;nbsp; &amp;nbsp;We've had 3-4 TAC cases about this and about the best advice they could provide was ...&amp;nbsp; don't wait very long to begin the upgrade on the Primary Panorama once the Secondary is done -- the shorter the time period in which the ES cluster's nodes are out of sync, the less shards they have to process in order to get back into sync. (Green)&amp;nbsp; &amp;nbsp; &amp;nbsp;There seems to be very little information out there regarding the ES cluster and issues such as this.&amp;nbsp; Here's my current ES Cluster health:&lt;/P&gt;
&lt;P&gt;(primary-active)&amp;gt; show log-collector-es-cluster health&lt;/P&gt;
&lt;P&gt;{&lt;BR /&gt;"cluster_name" : "__pan_cluster__",&lt;BR /&gt;"status" : "yellow",&lt;BR /&gt;"timed_out" : false,&lt;BR /&gt;"number_of_nodes" : 6,&lt;BR /&gt;"number_of_data_nodes" : 4,&lt;BR /&gt;"active_primary_shards" : 2506,&lt;BR /&gt;"active_shards" : 4886,&lt;BR /&gt;"relocating_shards" : 0,&lt;BR /&gt;"initializing_shards" : 47,&lt;BR /&gt;"unassigned_shards" : 83,&lt;BR /&gt;"delayed_unassigned_shards" : 0,&lt;BR /&gt;"number_of_pending_tasks" : 0,&lt;BR /&gt;"number_of_in_flight_fetch" : 0,&lt;BR /&gt;"task_max_waiting_in_queue_millis" : 0,&lt;BR /&gt;"active_shards_percent_as_number" : 97.40829346092504&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 16:31:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/454999#M596</guid>
      <dc:creator>Darren_Schubert</dc:creator>
      <dc:date>2021-12-22T16:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Status Red for log-collector-es-cluster health in M600</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/455045#M597</link>
      <description>&lt;P&gt;Good to know. I had to upgrade the Passive Panorama during the working hours to get the management's green light for upgrading the active panorama and LCs during the night, so the active Panorama upgrade started after 8 hours from the completion of the passive Panorama. However in my case, on one the log collectors the ES cluster was struggling to come up (the output for command&amp;nbsp;&lt;SPAN&gt;show log-collector-es-cluster health was empty or sometimes later cli was hanging or even one time crashed), at the end it took about 2 hours seeing the ES cluster to come up on that LC (show log-collector-es-cluster health worked fine for the first time and showed the expected outputs) and also at this time the FW logs started coming into Panorama. For my case all FWs immediately after the upgrades got connections to LC according to "show logging-status device xxx. TAC is saying the status of ES Cluster should change to green after having "active_shards_percent_as_number" at 100%. I guess I have to wait another 10 hours for this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 17:24:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/455045#M597</guid>
      <dc:creator>Mostafavi_DWR</dc:creator>
      <dc:date>2021-12-22T17:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Status Red for log-collector-es-cluster health in M600</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/480676#M849</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162441"&gt;@Mostafavi_DWR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have seen this issue on our environment multiple times. All the time TAC use to say upgrade the LC or reboot the hardware. But finally we came to know that elastic search process was keep on restarting. you can check it using "show system software status | match elasticsearch". In order to fix it you can use&amp;nbsp;debug "elasticsearch es-restart option all" once you restart it, it may take 5 to 10 mins to show the logs and 10 to 15 mins to show logs collector status in green. and as a final option you simply restart the Log collectors or in case Panorama is used a LC then restart the Panorama. I am assuming that all the necessary ports are already open so we'll not go into it. I hope this helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Kamal Modi&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 05:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/480676#M849</guid>
      <dc:creator>Kamal_Modi</dc:creator>
      <dc:date>2022-04-18T05:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Status Red for log-collector-es-cluster health in M600</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/1244284#M3013</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202666"&gt;@Kamal_Modi&lt;/a&gt;&amp;nbsp;I had similar issue where M200 Elastic search was red for more than 2 days when we upgrade the M200 from 11.1. to 11.2.7.&lt;/P&gt;
&lt;P&gt;I ran the command on Primary Panorama&lt;/P&gt;
&lt;P&gt;debug elasticsearch es-restart option all and then within 10 mins status changed to yellow&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2025 17:14:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/status-red-for-log-collector-es-cluster-health-in-m600/m-p/1244284#M3013</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2025-12-20T17:14:56Z</dc:date>
    </item>
  </channel>
</rss>

