Botnet report fails to generate on some devices

Botnet report fails to generate on some devices

13259
Created On 09/25/18 20:34 PM - Last Modified 06/09/23 09:09 AM


Symptom


Why is my botnet report not working?  

 

In some instances, a botnet report may fail to generate on a device. This can be verified by the following factors.

 

  • Botnet reports are not available for selection in bold on the report calendar located within Monitor > Botnet > Date
  • In mp-log > botnet.log content is not loaded
  • In mp-log > botnet.log the progress_file is empty
  • In mp-log > botnet.log the following error is returned: 
    failed: cannot open file /opt/pancfg/mgmt/av/botnet.db



Resolution


Several factors can prevent successful generation of the botnet report.

 

  1. Botnet reports have not been configured.
  2. No URL Filtering logs are present with a category of "malware".  These are necessary for botnet report correlation.
  3. There is no active AV content installed on the device.**
  4. The device does not have an active Threat Prevention (AV) license.**

** In scenarios 3 & 4 the following error will be present in mp-log > botnet.log:

failed: cannot open file /opt/pancfg/mgmt/av/botnet.db

 

The botnet.db (database) file is downloaded as part of Antivirus (AV) dynamic updates.  Without a valid Threat license or AV content on the device it is not possible to download the botnet.db file.  Therefore, one will not be able to successfully run or generate the botnet report.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhaCAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language