From yesterday(26.05.2021) in two independent environments on the firewall I can see messages: "Machine Learning engine for Phishing stopped, please update your content".
Does anyone have a similar problem and know how to fix it?
We are seeing the same alerts. I've been digging all morning trying to find any information available on this and coming up empty so far. Confirmed all content/signatures are updated to most recent versions.
Engine keeps starting, runs for about 9 minutes, and then stops and generates the alerts.
I have VM-100, PAN-OS 10.0.1 in my lab, after upgrade signatures as below I started receive these messages. It's looks like problem with Dynamic Updates.
Looks like it is resolved for us now. Last "stopped" messages were received at 2:31pm EST and all of the FWs last reported the engine starting. Nothing overly interesting in the system logs that looked different from previous connections to the update server or any content update delivery.
Upgrade to the latest 10.6 version as 10.x is still new and prone to issues.
In the Masterd log there could be some info for the process rebooting, also check if the managment plane has a log with the same name as the process name that you see in Masterd log if not check in the GUI the system log. Also monitor your dataplane and managment plane CPU and the memory as it could be memory or cpu leakage bug. You may use the Palo Alto chrome extension for better monitoring:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!