Wrong information in ACC tab compared to data collected in custom reports
Symptom
ACC tab is not displaying expected data in different periods of query
Environment
All PANOS
All Platforms
Cause
On FW, there are 4 levels of summary roll up:
- Log-receiver daemon generates the 15 minutes summary logs for traffic, thread, and url at 15, 30, 45, and 60 minutes of the hour. In low end platforms summary logs are limited to 100K. High end platforms can support 600K logs. We allow up to 5 flash per 15 minutes period.
- At the beginning of the hour, hourly summary logs are generated based on the past hour's 15 minutes summary logs, with the same limit for logs, there is 4-to-1 summary, data loss could happen during the flash process
- At the beginning of the day, daily summary logs are generated based on the past day's hourly summary logs with the same limit for logs, there is 24-to-1 summary.
- at beginning of Sunday, weekly summary logs are generated based on the past week's daily summary logs with the same limit for the logs, there is 7-to-1 summary.
When we generate reports based on summary logs (most of ACC reports are based on summary logs), the backend tries to use the largest summary logs which cover the reporting period. For example On a 30 days report, the backend tries to use the weekly summary logs for the week within the reporting period, then daily for the remaining period, then hourly, finally using the 15 minutes summary (we call it summary log) for the two remaining ends.
The purpose for doing this is to speed up the report generation, the side effect is the report are not accurate, especially when we compare the result for the different reporting period, such as 7-day report to 30-days report. or 7-day report to 7-calendar-day report
Resolution
To get more accurate data, customer should create custom report using detailed logs, such as traffic, threat, url, etc.