Server and Client Logging for Traps

Server and Client Logging for Traps

0
Created On 09/25/18 18:19 PM - Last Modified 07/19/22 23:09 PM


Symptom


The Traps logs can be referenced to provide a deeper understanding of the system and the issues that are encountered.



Resolution


Details

On the ESMServer, the Traps's logs (Core log - Server.log ,Console log - DebugWeb.log) are located at:

C:\ProgramData\Cyvera\Logs


On the Traps client machine:

Service.log

  • Windows Vista and above
    C:\ProgramData\Cyvera\Logs
  • Windows XP
    C:\Document and Settings\All Users\Application Data\Cyvera\Logs

Console.log

  • Windows Vista and above
    C:\Users\<USERNAME>\AppData\Roaming\Cyvera
  • Windows XP
    C:\Document and Settings\<USERNAME>\Application Data\Cyvera\Logs


Log analysis

There are few ways to search for issues in the Traps logs.

  1. Search the logs for keywords.
    The following words point to and describe their severity:
    • TRACE
    • DEBUG
    • INFO
    • WARN
    • ERROR     << found in most cases
    • FATAL
  2. Search the problem in the log by looking for any change in the order of the notifications:
    log.png


Known log entries on Traps (Service.log)

Starting service

Keywords: "CyveraService service started"

starting service log.png

 

Policy updated

Keywords: "update policy"

update policy log.png

 

Prevention log

Keywords: "prevention received"

prevention log.png

 

One time action log

Keywords: "Executing one time actionParameters"

onetimeaction log.png

 

Process flow

Keywords: "ProcessNotification called"

processflow.png

 

WildFire check

Keywords: "wildfire.wildfire Hash"

wildfire check.png

 

No connection to server

Keywords: "Failed contacting server"

noconnctionto server.png

 

Known log entries on ESM Server (Server.log)

Starting service

Keywords: "Starting Service"

servicestartingserver.png

 

Updating client policy

Keywords: "GetPolicyFinal"

updating policy server.png

 

Heartbeat from client

Keywords: "Heartbeat call from machine"

hearbeat.png

 

Getting prevention from client

Keywords: "prevention"

prevention from server.png

 

Action done

Keywords "ReportImmidiateActionDone"

actiondone.png

 

Wildfire hash inspection

Keywords: "wildfire result for hash"

wild hash.png

 

No connection to DB

no coonction to db.png

 

No connection to Wildfire

no connectionto wildfire.png



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClPbCAK&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail