How Can I Check the Report Generation Process?
25840
Created On 04/16/19 13:43 PM - Last Modified 03/25/22 03:41 AM
Question
Reports are not generating as expected; can we check the logs related to report generation on the firewall?
Environment
- Palo Alto Networks Firewall
- Panorama
- PAN-OS 8.1, 9.0 and 9.1 only.
Answer
Report generation is a sub-process performed by the mgmtsrv process. Logs will not be visible from the system log in the web interface. In order to track the sub-process, debugging needs to be enabled.
- Here's how to show the current debug level:
admin@firewall> debug management-server show
management-server debug:info
Features:
- To enable debug logs, run this command:
admin@firewall > debug management-server set report basic
success: management-server debug set report :basic
admin@firewall > debug management-server set report detail
success: management-server debug set report :detail
admin@firewall > debug management-server on debug
management-server debug:debug
- Review the debug settings:
admin@firewall> debug management-server show
management-server debug:debug
Features:
report : basic detail
- To check the live logs, run this:
admin@firewall > tail follow yes mp-log ms.log
- To read the full historical log, run this:
admin@firewall > less mp-log ms.log
- To reset the default debug level (to ensure historical data is not overwritten by the increased logging level), run this command:
admin@firewall> debug management-server unset all
success: management-server debug unset all :
admin@firewall> debug management-server on info
management-server debug:info