<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are logs lost when log discarded (queue full) increases? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/are-logs-lost-when-log-discarded-queue-full-increases/m-p/510758#M106258</link>
    <description>&lt;P&gt;this does indeed mean that logs are being discarded (lost)&lt;/P&gt;
&lt;P&gt;you could look into decreasing logging on some extremely chatty applications like DNS by creating a rule specific to these applications and disabling logging&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 09:58:36 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2022-08-04T09:58:36Z</dc:date>
    <item>
      <title>Are logs lost when log discarded (queue full) increases?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-logs-lost-when-log-discarded-queue-full-increases/m-p/510748#M106253</link>
      <description>&lt;P&gt;Hi everyone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I changed last week from pa-3020 to pa-3220.&lt;BR /&gt;However, the log looks abnormal (7-8 minutes delay).&lt;BR /&gt;Looking at the log-receiver status with the command below, log discarded (queue full) is continuously increasing.&lt;BR /&gt;Does this mean log loss?&lt;BR /&gt;How can I solve this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@PA-3220(active)&amp;gt; debug log-receiver statistics &lt;BR /&gt;&lt;BR /&gt;Logging statistics&lt;BR /&gt;------------------------------ -----------&lt;BR /&gt;Log incoming rate: 223/sec&lt;BR /&gt;Log written rate: 800/sec&lt;BR /&gt;Corrupted packets: 0&lt;BR /&gt;Corrupted URL packets: 0&lt;BR /&gt;Corrupted HTTP HDR packets: 0&lt;BR /&gt;Corrupted HTTP HDR Insert packets: 0&lt;BR /&gt;Corrupted EMAIL HDR packets: 0&lt;BR /&gt;Logs discarded (queue full): 429312640&amp;nbsp; &lt;STRONG&gt;&amp;lt;&amp;lt;&amp;lt; continuously increasing&lt;/STRONG&gt;&lt;BR /&gt;Traffic logs written: 17568093&lt;BR /&gt;GTP logs written: 0&lt;BR /&gt;Tunnel logs written: 0&lt;BR /&gt;Auth logs written: 0&lt;BR /&gt;Config logs written: 1&lt;BR /&gt;System logs written: 15306&lt;BR /&gt;Alarm logs written: 0&lt;BR /&gt;Userid logs written: 1112654&lt;BR /&gt;SCTP logs written: 0&lt;BR /&gt;GlobalProtect logs written: 0&lt;BR /&gt;DECRYPTION logs written: 0&lt;BR /&gt;URL logs written: 503413&lt;BR /&gt;Wildfire logs written: 12&lt;BR /&gt;Anti-virus logs written: 0&lt;BR /&gt;Maching Learning-virus logs written: 0&lt;BR /&gt;Wildfire Anti-virus logs written: 0&lt;BR /&gt;Spyware logs written: 366410&lt;BR /&gt;Spyware-DNS logs written: 0&lt;BR /&gt;Attack logs written: 0&lt;BR /&gt;Vulnerability logs written: 0&lt;BR /&gt;Data logs written: 0&lt;BR /&gt;Wif logs written: 0&lt;BR /&gt;Fileext logs written: 1632&lt;BR /&gt;Fileext logs URL not written: 1632&lt;BR /&gt;Fileext logs URL not written (timedout): 0&lt;BR /&gt;URL cache age out count: 0&lt;BR /&gt;URL cache full count: 0&lt;BR /&gt;URL cache key exist count: 143&lt;BR /&gt;URL cache wrt incomplete http hdrs count: 0&lt;BR /&gt;URL cache rcv http hdr before url count: 0&lt;BR /&gt;URL cache full drop count(url log not received): 0&lt;BR /&gt;URL cache age out drop count(url log not received): 0&lt;BR /&gt;Email hdr cache count: 0&lt;BR /&gt;Email hdr cache hit count: 0&lt;BR /&gt;HTTP hdr insertion received: 0&lt;BR /&gt;HTTP hdr insertion processed: 0&lt;BR /&gt;HTTP hdr insert no URL drop count: 0&lt;BR /&gt;HTTP hdr insert with invalid URL log: 0&lt;BR /&gt;HTTP hdr insert with values exceeded max allowed length: 0&lt;BR /&gt;Traffic alarms dropped due to sysd write failures: 0&lt;BR /&gt;Traffic alarms dropped due to global rate limiting: 0&lt;BR /&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;BR /&gt;Traffic alarms generated count: 0&lt;BR /&gt;Netflow incoming count: 54975992&lt;BR /&gt;Log Forward count: 0&lt;BR /&gt;Log Forward discarded (queue full) count: 0&lt;BR /&gt;Log Forward discarded (send error) count: 0&lt;BR /&gt;Total logs not written due to disk unavailability: 0&lt;BR /&gt;Logs not written since disk became unavailable: 0&lt;BR /&gt;HIP Report logs received: 0&lt;BR /&gt;&lt;BR /&gt;Summary Statistics:&lt;BR /&gt;Num current entries in trsum:8544&lt;BR /&gt;Num cumulative entries in trsum:9546424&lt;BR /&gt;Num current entries in thsum:1018&lt;BR /&gt;Num cumulative entries in thsum:869823&lt;BR /&gt;Num current entries in urlsum:0&lt;BR /&gt;Num cumulative entries in urlsum:0&lt;BR /&gt;Num current entries in gtpsum:0&lt;BR /&gt;Num cumulative entries in gtpsum:0&lt;BR /&gt;Num current entries in sctpsum:0&lt;BR /&gt;Num cumulative entries in sctpsum:0&lt;BR /&gt;Num current drop entries in trsum:0&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 08:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-logs-lost-when-log-discarded-queue-full-increases/m-p/510748#M106253</guid>
      <dc:creator>hyeongchanlee</dc:creator>
      <dc:date>2022-08-04T08:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs lost when log discarded (queue full) increases?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-logs-lost-when-log-discarded-queue-full-increases/m-p/510758#M106258</link>
      <description>&lt;P&gt;this does indeed mean that logs are being discarded (lost)&lt;/P&gt;
&lt;P&gt;you could look into decreasing logging on some extremely chatty applications like DNS by creating a rule specific to these applications and disabling logging&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 09:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-logs-lost-when-log-discarded-queue-full-increases/m-p/510758#M106258</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-08-04T09:58:36Z</dc:date>
    </item>
  </channel>
</rss>

