<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: aggressive-cleaning enable  but still got disk usage email alert? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259358#M73544</link>
    <description>&lt;P&gt;Right now it is after hours and logging rate is low as users are gone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is info from that command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug log-receiver statistics&lt;/P&gt;&lt;P&gt;Logging statistics&lt;BR /&gt;------------------------------ -----------&lt;BR /&gt;Log incoming rate: 83/sec&lt;BR /&gt;Log written rate: 83/sec&lt;BR /&gt;Corrupted packets: 0&lt;BR /&gt;Corrupted URL packets: 0&lt;BR /&gt;Corrupted HTTP HDR packets: 0&lt;BR /&gt;Corrupted EMAIL HDR packets: 0&lt;BR /&gt;Logs discarded (queue full): 0&lt;BR /&gt;Traffic logs written: 124003056&lt;BR /&gt;GTP logs written: 0&lt;BR /&gt;Tunnel logs written: 0&lt;BR /&gt;Auth logs written: 0&lt;BR /&gt;Userid logs written: 11898465&lt;BR /&gt;URL logs written: 5368&lt;BR /&gt;Wildfire logs written: 193&lt;BR /&gt;Anti-virus logs written: 0&lt;BR /&gt;Widfire Anti-virus logs written: 0&lt;BR /&gt;Spyware logs written: 16432611&lt;BR /&gt;Spyware-DNS logs written: 0&lt;BR /&gt;Attack logs written: 0&lt;BR /&gt;Vulnerability logs written: 1923724&lt;BR /&gt;Fileext logs written: 0&lt;BR /&gt;Fileext logs URL not written: 0&lt;BR /&gt;Fileext logs URL not written (timedout): 0&lt;BR /&gt;URL cache age out count: 0&lt;BR /&gt;URL cache full count: 0&lt;BR /&gt;URL cache key exist count: 0&lt;BR /&gt;URL cache wrt incomplete http hdrs count: 0&lt;BR /&gt;URL cache rcv http hdr before url count: 0&lt;BR /&gt;URL cache full drop count(url log not received): 0&lt;BR /&gt;URL cache age out drop count(url log not received): 0&lt;BR /&gt;Email hdr cache count: 127&lt;BR /&gt;Email hdr cache hit count: 124&lt;BR /&gt;Traffic alarms dropped due to sysd write failures: 0&lt;BR /&gt;Traffic alarms dropped due to global rate limiting: 0&lt;BR /&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;BR /&gt;Traffic alarms generated count: 0&lt;BR /&gt;Netflow incoming count: 0&lt;BR /&gt;Log Forward count: 501&lt;BR /&gt;Log Forward discarded (queue full) count: 0&lt;BR /&gt;Log Forward discarded (send error) count: 0&lt;BR /&gt;Total logs not written due to disk unavailability: 0&lt;BR /&gt;Logs not written since disk became unavailable: 0&lt;/P&gt;&lt;P&gt;Summary Statistics:&lt;BR /&gt;Num current drop entries in trsum:0&lt;BR /&gt;Num cumulative drop entries in trsum:0&lt;BR /&gt;Num current drop entries in thsum:0&lt;BR /&gt;Num cumulative drop entries in thsum:0&lt;BR /&gt;Num current drop entries in gtpsum:0&lt;BR /&gt;Num cumulative drop entries in gtpsum:0&lt;/P&gt;&lt;P&gt;External Forwarding stats:&lt;BR /&gt;Type Enqueue Count Send Count Drop Count Queue Depth Send Rate(last 1min)&lt;BR /&gt;syslog 266368006 266368006 0 0 14796&lt;BR /&gt;snmp 0 0 0 0 0&lt;BR /&gt;email 0 0 0 0 0&lt;BR /&gt;raw 142364950 142364950 0 0 7906&lt;BR /&gt;http 0 0 0 0 0&lt;BR /&gt;autotag 0 0 0 0 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are only logging at sessiond end.&lt;/P&gt;&lt;P&gt;also we are logging at default deny rule&lt;/P&gt;&lt;P&gt;also we have logging for intrazone enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is not much ntp or dns traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i verify that the logging rate at peak time is high for PA 5050?&lt;/P&gt;&lt;P&gt;Any baseline i could check?&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2019 00:32:09 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-05-01T00:32:09Z</dc:date>
    <item>
      <title>aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259143#M73484</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have configured the command below&amp;nbsp; but still got email alert&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;model: PA-5050&lt;BR /&gt;sw-version: 8.0.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-NGFW-1(active)&amp;gt; show system state | match aggressive-cleaning&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;cfg.debug-sw-du.config: { 'aggressive-cleaning': True, }&lt;/P&gt;&lt;P&gt;domain: 1&lt;BR /&gt;receive_time: 2019/04/29 05:03:23&lt;BR /&gt;serial: 002201001803&lt;BR /&gt;seqno: 6880362&lt;BR /&gt;actionflags: 0x8000000000000000&lt;BR /&gt;type: SYSTEM&lt;BR /&gt;subtype: general&lt;BR /&gt;config_ver: 0&lt;BR /&gt;time_generated: 2019/04/29 05:03:23&lt;BR /&gt;dg_hier_level_1: 0&lt;BR /&gt;dg_hier_level_2: 0&lt;BR /&gt;dg_hier_level_3: 0&lt;BR /&gt;dg_hier_level_4: 0&lt;BR /&gt;vsys_name:&lt;BR /&gt;device_name: NGFW-1&lt;BR /&gt;vsys_id: 0&lt;BR /&gt;vsys:&lt;BR /&gt;eventid: general&lt;BR /&gt;object:&lt;BR /&gt;fmt: 0&lt;BR /&gt;id: 0&lt;BR /&gt;module: general&lt;BR /&gt;severity: critical&lt;BR /&gt;opaque: Disk usage for / exceeds limit, 96 percent in use, cleaning filesystem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought when you configure aggressive cleaning it should do this automaticalls and we should not get email alert?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 20:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259143#M73484</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-04-29T20:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259191#M73499</link>
      <description>&lt;P&gt;I have to get this out of the way first: Please upgrade to a more current code version. 8.0.9 was released over a year ago and has &lt;A href="https://securityadvisories.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;several vulnerabilities&lt;/A&gt; at medium or high priority. Unpatched devices are the most common vectors for attacks. Also, 8.0 has &lt;A href="https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary" target="_blank" rel="noopener"&gt;six months&lt;/A&gt; before it is End of Life as well, so that might be a good opportunity to begin upgrading to 8.1, which is supported on the PA-5000 series &lt;A href="https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates" target="_blank" rel="noopener"&gt;until 2024&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0002 (High). Cross site scripting (XSS) vulnerability in the management interface. Fixed in 8.0.15.&lt;/P&gt;&lt;P&gt;PAN-SA-2018-0008 (High). Denial of Service (DoS) in the management interface. Fixed in 8.0.10.&lt;/P&gt;&lt;P&gt;PAN-SA-2018-0009 (medium). XSS in the GP login page. Fixed in 8.0.11.&lt;/P&gt;&lt;P&gt;PAN-SA-2018-0015 (medium). OpenSSL vulnerabilities. Fixed in 8.0.13.&lt;/P&gt;&lt;P&gt;PAN-SA-2018-0012 (medium). FragmentSmack vulnerability. Fixed in 8.0.13.&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0001 (medium). XSS in external dynamic lists. Fixed in 8.0.15.&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0007 (medium). DoS in the management interface. Fixed in 8.0.16.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With that said, it depends on how much logging you are doing. Check your logging rate (debug log-receiver statistics) to see where you're at for logs/second. Even with aggressive cleaning the system may simply be getting so many logs it cannot keep up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may be able to reduce that as well. Make sure you're not logging at session start, don't log on the default deny rule (logging is disabled by default on it). You may also want to exclude logging for things like NTP, DNS, Ping, etc. by disabling the 'log at session end' in a rule dedicated just to that type of traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 00:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259191#M73499</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-04-30T00:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259199#M73501</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually you should edit the rule for the email logging, by adding a AND condition with negate option on the descrtiption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 04:53:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259199#M73501</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2019-04-30T04:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259358#M73544</link>
      <description>&lt;P&gt;Right now it is after hours and logging rate is low as users are gone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is info from that command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug log-receiver statistics&lt;/P&gt;&lt;P&gt;Logging statistics&lt;BR /&gt;------------------------------ -----------&lt;BR /&gt;Log incoming rate: 83/sec&lt;BR /&gt;Log written rate: 83/sec&lt;BR /&gt;Corrupted packets: 0&lt;BR /&gt;Corrupted URL packets: 0&lt;BR /&gt;Corrupted HTTP HDR packets: 0&lt;BR /&gt;Corrupted EMAIL HDR packets: 0&lt;BR /&gt;Logs discarded (queue full): 0&lt;BR /&gt;Traffic logs written: 124003056&lt;BR /&gt;GTP logs written: 0&lt;BR /&gt;Tunnel logs written: 0&lt;BR /&gt;Auth logs written: 0&lt;BR /&gt;Userid logs written: 11898465&lt;BR /&gt;URL logs written: 5368&lt;BR /&gt;Wildfire logs written: 193&lt;BR /&gt;Anti-virus logs written: 0&lt;BR /&gt;Widfire Anti-virus logs written: 0&lt;BR /&gt;Spyware logs written: 16432611&lt;BR /&gt;Spyware-DNS logs written: 0&lt;BR /&gt;Attack logs written: 0&lt;BR /&gt;Vulnerability logs written: 1923724&lt;BR /&gt;Fileext logs written: 0&lt;BR /&gt;Fileext logs URL not written: 0&lt;BR /&gt;Fileext logs URL not written (timedout): 0&lt;BR /&gt;URL cache age out count: 0&lt;BR /&gt;URL cache full count: 0&lt;BR /&gt;URL cache key exist count: 0&lt;BR /&gt;URL cache wrt incomplete http hdrs count: 0&lt;BR /&gt;URL cache rcv http hdr before url count: 0&lt;BR /&gt;URL cache full drop count(url log not received): 0&lt;BR /&gt;URL cache age out drop count(url log not received): 0&lt;BR /&gt;Email hdr cache count: 127&lt;BR /&gt;Email hdr cache hit count: 124&lt;BR /&gt;Traffic alarms dropped due to sysd write failures: 0&lt;BR /&gt;Traffic alarms dropped due to global rate limiting: 0&lt;BR /&gt;Traffic alarms dropped due to each source rate limiting: 0&lt;BR /&gt;Traffic alarms generated count: 0&lt;BR /&gt;Netflow incoming count: 0&lt;BR /&gt;Log Forward count: 501&lt;BR /&gt;Log Forward discarded (queue full) count: 0&lt;BR /&gt;Log Forward discarded (send error) count: 0&lt;BR /&gt;Total logs not written due to disk unavailability: 0&lt;BR /&gt;Logs not written since disk became unavailable: 0&lt;/P&gt;&lt;P&gt;Summary Statistics:&lt;BR /&gt;Num current drop entries in trsum:0&lt;BR /&gt;Num cumulative drop entries in trsum:0&lt;BR /&gt;Num current drop entries in thsum:0&lt;BR /&gt;Num cumulative drop entries in thsum:0&lt;BR /&gt;Num current drop entries in gtpsum:0&lt;BR /&gt;Num cumulative drop entries in gtpsum:0&lt;/P&gt;&lt;P&gt;External Forwarding stats:&lt;BR /&gt;Type Enqueue Count Send Count Drop Count Queue Depth Send Rate(last 1min)&lt;BR /&gt;syslog 266368006 266368006 0 0 14796&lt;BR /&gt;snmp 0 0 0 0 0&lt;BR /&gt;email 0 0 0 0 0&lt;BR /&gt;raw 142364950 142364950 0 0 7906&lt;BR /&gt;http 0 0 0 0 0&lt;BR /&gt;autotag 0 0 0 0 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are only logging at sessiond end.&lt;/P&gt;&lt;P&gt;also we are logging at default deny rule&lt;/P&gt;&lt;P&gt;also we have logging for intrazone enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is not much ntp or dns traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i verify that the logging rate at peak time is high for PA 5050?&lt;/P&gt;&lt;P&gt;Any baseline i could check?&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 00:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259358#M73544</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-01T00:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259359#M73545</link>
      <description>&lt;P&gt;can you please explain in more detail about email logging?&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 00:34:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259359#M73545</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-01T00:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259559#M73581</link>
      <description>&lt;P&gt;what is the config you have done to receive the alerts by email?&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 02:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259559#M73581</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2019-05-02T02:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259560#M73582</link>
      <description>&lt;P&gt;please follow this link.&lt;/P&gt;&lt;P&gt;You can choose what sev you want for email alert&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/configure-email-alerts" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/configure-email-alerts&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 02:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259560#M73582</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-02T02:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259561#M73583</link>
      <description>&lt;P&gt;ok, then in the log settings, you have "filter builder".&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 02:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259561#M73583</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2019-05-02T02:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: aggressive-cleaning enable  but still got disk usage email alert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259562#M73584</link>
      <description>&lt;P&gt;yes like&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sev equal critical&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 02:31:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aggressive-cleaning-enable-but-still-got-disk-usage-email-alert/m-p/259562#M73584</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-02T02:31:16Z</dc:date>
    </item>
  </channel>
</rss>

