Log forwarding delays or Missing Logs due to high latency between log collectors in a collector group
99475
Created On 12/28/18 08:30 AM - Last Modified 12/31/25 10:28 AM
Symptom
A Collector Group's ability to handle logs can suffer greatly when the latency between log collectors in the collector group is greater than 10 ms and/or when the logging rate is high. Under such conditions, a slowness or delay might be seen when forwarding logs. In some instances, logs may even get lost.
Environment
Environments where this issue is more likely to occur:
- Latency is high between LCs – a latency greater than 10ms could trigger the problem.
- High logging rate – high end FWs (PA-7k, PA-5200), forwarding logs to LC or many firewalls forwarding logs
- Log redundancy is set.
Cause
Resolution
Solution
Ensure at least 10ms latency between log collectors.
Workaround
- Turn off Log Redundancy for CG
Redundancy doubles the traffic volume between the LCs. Reducing the traffic may help ease the pressure.
-
Turn on Inter-LC Data Compression
Data compression for inter-LC is the default for 8.1. In 8.0, do the following to turn on the data compression for inter-LC communication on all the LCs in the group:
debug log-collector inter-log-collector data-compression debug software restart process logd
There is no operational impact, but can result in minimal increase of CPU usage of logd.
-
Split a single Collector Group into multiple Collector Groups
It reduces or in some cases completely eliminates the inter-log collector communication, therefore mitigating the likelihood of this problem. It has no operational impact as long as all the log collectors are up and running. If one of the log collectors goes down briefly, firewalls (other than PA-7k and PA-5200) will re-forward the logs and logs will not be lost.
Note: This workaround will impact log forwarding from PA-7K and PA-5200s. Due to buffer capability and extremely high logging rate of these FWs, buffers can get full and they may not be able to re-forward the logs to the log collector once it comes back up.
Note: This workaround will impact log forwarding from PA-7K and PA-5200s. Due to buffer capability and extremely high logging rate of these FWs, buffers can get full and they may not be able to re-forward the logs to the log collector once it comes back up.