<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: intermittent dataplane CPU spike in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304142#M79107</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's exactly what I mean. Unless you can narrow down what interface is seeing the increased traffic load so you can limit it to one particular interface. The pan(a)wchrome Chrome extension can monitor some of this information for you to possibly narrow it to a particular interface before you enable netflow so you don't have to enable it across all of them though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason you wouldn't want to do it directly on the firewall is because the process is CPU intensive and always raises the possibility for firewall performance degradation.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2019 21:29:39 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-12-17T21:29:39Z</dc:date>
    <item>
      <title>intermittent dataplane CPU spike</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304132#M79103</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing the dataplane cpu spike to over 90% for about 5 minutes and then drop to normal. It comes intermittently with not regularity to when it occurs. I have been doing the show running resource-monitor, show system statistics,&amp;nbsp; and showing the 20 top applications and I can not find it. Any suggestions would be helpful&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 21:12:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304132#M79103</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2019-12-17T21:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: intermittent dataplane CPU spike</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304133#M79104</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'd recommend setting up netflow collection on your interfaces so you get a better insight into the traffic during these spikes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it's spiking for an extended period you could possibly tap the uplinks to the firewall and do a packet capture to really gain a good insight into what type of traffic is coming across and when, but you probably wouldn't want to do that packet capture directly on the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 21:17:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304133#M79104</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-17T21:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: intermittent dataplane CPU spike</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304138#M79105</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you mean using solarwinds or something to do a netflow collections on all the pa interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why not do firewall packet capture on the firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 21:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304138#M79105</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2019-12-17T21:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: intermittent dataplane CPU spike</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304142#M79107</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's exactly what I mean. Unless you can narrow down what interface is seeing the increased traffic load so you can limit it to one particular interface. The pan(a)wchrome Chrome extension can monitor some of this information for you to possibly narrow it to a particular interface before you enable netflow so you don't have to enable it across all of them though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason you wouldn't want to do it directly on the firewall is because the process is CPU intensive and always raises the possibility for firewall performance degradation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2019 21:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-dataplane-cpu-spike/m-p/304142#M79107</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-17T21:29:39Z</dc:date>
    </item>
  </channel>
</rss>

