- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-08-2014 02:05 PM
Hi all,
We had an issue today where we noticed the logging data stopped displaying in the Pan OS GUI (PA-500).. One thing we noticed is after committing a config change, it looks like the firewall was in the process of doing a sync with the backup device. I assume to resolve this problem we need to restart the dataplane? I'm surprised it allowed the commit to occur if a sync was in progress.
Bryan
07-08-2014 02:55 PM
Hello Bino,
Yes, you can run those 2 commands while the FW is UP. It would not impact to the data-plane traffic ( user's traffic through PAN firewall), because daemons are running on Management-plane. For safer side, you may restart log-receiver and management server process after the business hrs.
Thanks
07-08-2014 02:09 PM
Logging is handled by the log receiver.
> debug software restart log-receiver
You can check statistics here to see which are not working.
>debug log-receiver statistics
07-08-2014 02:17 PM
Hello Bino,
Could you please check below mentioned command:
> show logging-status >>>>>>>>> Check last forwarded logs date and time
> debug log-receiver statistics ------ check if below mentioned counters are incrementing
Log Forward discarded (queue full) count: 0 >>>>
Log Forward discarded (send error) count: 0 >>>>
>debug software restart log-receiver
if no change still;
>debug software restart management-server ---- after applying this command, wait for a few minutes. It will log you out from CLI and GUI.
Thanks
07-08-2014 02:41 PM
Thanks Guys,
I assume the debug software restart log-receiver can be done while the firewall is up? We were thinking of waiting until after business hours do this. Any idea what would cause this issue? I assume maybe it was committing a change at the same time as the sync.
07-08-2014 02:55 PM
Hello Bino,
Yes, you can run those 2 commands while the FW is UP. It would not impact to the data-plane traffic ( user's traffic through PAN firewall), because daemons are running on Management-plane. For safer side, you may restart log-receiver and management server process after the business hrs.
Thanks
07-08-2014 05:07 PM
Hulk we still seem to have an issue. I ran both debug software restart log-receiver which did not resolve the issue. Same with debug software restart management-server.
if I run debug log-receiver statistics I get the following error see dagger log. Do I need to do this plugged in to the cli port directly. I'm doign this via telnet from my workstation on the LAN.
07-08-2014 05:12 PM
Hello Bino,
If you restart the management-server daemon, you have to wait for a few minutes. It will automatically log out from CLI (SSH), since SSH/web-UI is managed by mgmt-server process. So, please re-login into the PAN firewall and then check with CLI command >debug log-receiver statistics
Thanks
07-08-2014 05:17 PM
Just logged in again and the error is still coming up. its been a few minutes now,
debug log-receiver statisitcs
Server error: An error occurred. See dagger.log for information.
07-08-2014 05:28 PM
Could you please check CLI command o/p of > show ntp
It should show the NTP server, it's connected.
Related DOC:
Error in NTP Sync Status Display
Let me know the result.
Thanks
07-08-2014 05:29 PM
Think I need to contact support for this. Thanks for the help
07-08-2014 05:33 PM
The mentioned error messages are related to NTP. Hence, could you please check the status of the NTP server on your FW.
Server error: An error occurred. See dagger.log for information
Thanks
07-08-2014 05:37 PM
Low and behold the log information is coming through now. I'm still getting the Server error: An error occurred. See dagger.log for information running debug log-receiver statistics from CLI though.
07-08-2014 05:39 PM
Interesting I am showing connected false for NTP
admin@PA-500(active)> show ntp
NTP state:
NTP synched to LOCAL
NTP server 0.north-america.pool.ntp.org connected: False
NTP server 1.north-america.pool.ntp.org connected: False
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!