Thank you. URL logs written: 10537835 Then a little later URL logs written: 10560883 However, there are no URL logs for the last 6 hours in the web interface view. The output from the other command leads me to believe we aren't dropping URL log requests. Current read idx: 23604 Current write idx: 23604 Total URL processed: 89140 Total URL received: 89140 Total URL request loss: 0 Total URL request discard: 0 Current async read idx: 39227 Current async write idx: 39227 Total async URL processed: 39227 Total async URL received: 39227 Total async URL request discard: 0 debug software restart device-server - this did knock off all my Citrix Xenapp/Xendesktop users. I think this is because I have SSL decryption of this traffic enabled on the PA. This did not resolve the issue. I'm not certain how to read the logdb-quota output. If I am reading it correctly, I am full because the threat logs exceed my 19GB qouta, and URL filtering goes to the threat logs. Quotas: traffic: 31.00%, 36.932 GB threat: 16.00%, 19.061 GB system: 4.00%, 4.765 GB config: 4.00%, 4.765 GB alarm: 3.00%, 3.574 GB trsum: 7.00%, 8.339 GB hourlytrsum: 3.00%, 3.574 GB dailytrsum: 1.00%, 1.191 GB weeklytrsum: 1.00%, 1.191 GB thsum: 2.00%, 2.383 GB hourlythsum: 1.00%, 1.191 GB dailythsum: 1.00%, 1.191 GB weeklythsum: 1.00%, 1.191 GB appstat: 6.00%, 7.148 GB userid: 1.00%, 1.191 GB hipmatch: 3.00%, 3.574 GB application-pcaps: 1.00%, 1.191 GB threat-pcaps: 1.00%, 1.191 GB debug-filter-pcaps: 1.00%, 1.191 GB hip-reports: 1.00%, 1.191 GB dlp-logs: 1.00%, 1.191 GB Disk usage: traffic: Logs: 15G, Index: 16G threat: Logs: 9.3G, Index: 11G system: Logs: 207M, Index: 43M config: Logs: 1.3G, Index: 9.9M alarm: Logs: 72K, Index: 36K trsum: Logs: 4.2G, Index: 4.3G hourlytrsum: Logs: 3.1G, Index: 412M dailytrsum: Logs: 1.1G, Index: 147M weeklytrsum: Logs: 1.1G, Index: 148M thsum: Logs: 2.4G, Index: 79M hourlythsum: Logs: 56M, Index: 42M dailythsum: Logs: 34M, Index: 40M weeklythsum: Logs: 24M, Index: 9.0M appstatdb: Logs: 288M, Index: 125M userid: Logs: 1.2G, Index: 440K hipmatch: Logs: 16K, Index: 16K application-pcaps: 681M threat-pcaps: 4.0K debug-filter-pcaps: 8.0K dlp-logs: 4.0K hip-reports: 1.1M wildfire: 4.0K show log threat - this shows that I have logs going back to 12/11/2013. I lowered the threat DB from 16% to 7% and then did a commit. After the commit, an Exec task ran for some time. After the Exec task completed, I started receiving URL filtering logs again. I believe reducing the threat DB caused the database purge to occur. I increased the threat DB back to 16% and did another commit. This seems to be a work around for this issue.
... View more