How Can I Check the Report Generation Process?

How Can I Check the Report Generation Process?

21581
Created On 04/16/19 13:43 PM - Last Modified 03/25/22 03:41 AM


Question


Reports are not generating as expected; can we check the logs related to report generation on the firewall?
 
 


Environment


  • Palo Alto Networks Firewall
  • Panorama
  • PAN-OS 8.1, 9.0 and 9.1 only.
 
 


Answer


Report generation is a sub-process performed by the mgmtsrv process. Logs will not be visible from the system log in the web interface. In order to track the sub-process, debugging needs to be enabled.

  1. Here's how to show the current debug level:
admin@firewall> debug management-server show

management-server debug:info
  Features:

 

  1. To enable debug logs, run this command:
admin@firewall > debug management-server set report basic

success: management-server debug set report :basic
admin@firewall > debug management-server set report detail 

success: management-server debug set report :detail
admin@firewall > debug management-server on debug

management-server debug:debug

 

  1. Review the debug settings:
admin@firewall> debug management-server show

management-server debug:debug
  Features:
    report  : basic detail

 

  1. To check the live logs, run this:
admin@firewall > tail follow yes mp-log ms.log

 

  1. To read the full historical log, run this:
admin@firewall > less mp-log ms.log

 

  1. To reset the default debug level (to ensure historical data is not overwritten by the increased logging level), run this command:
admin@firewall> debug management-server unset all
success: management-server debug unset all :

admin@firewall> debug management-server on info
management-server debug:info
 


Additional Information


 
 
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLc4CAG&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language