Failed to send telemetry data with error: CDL Receiver Key Empty

Failed to send telemetry data with error: CDL Receiver Key Empty

18250
Created On 07/29/23 20:22 PM - Last Modified 10/09/25 20:14 PM


Symptom


  • Failed to send telemetry data with error: CDL Receiver Key Empty.
  • From device_telemetry_curl.log, the response is empty:
    2023-05-18 20:44:11,445 dt INFO S1: CDL: RSP KEY RESPONSE: []


Environment


  • Palo Alto Networks firewalls.
  • All PAN-OS versions.


Cause


Traffic is not allowed on the firewalls to successfully send telemetry data to AIOps.
 


Resolution


Allow TCP ports and FQDNs required for Cortex data lake (CDL) to successfully send telemetry data to AIOps for NGFWs.

Required FQDNS:

  • *.prod.di.paloaltonetworks.cloud
  • *.paloaltonetworks.com
  • *.prod.di.paloaltonetworks.com
  • *.prod.reporting.paloaltonetworks.com
  • *.receiver.telemetry.paloaltonetworks.com
  • lic.lc.prod.us.cs.paloaltonetworks.com (if US based)
  • br-prd1.us.cdl.paloaltonetworks.com (if US based)
  • api.paloaltonetworks.com
  • apitrusted.paloaltonetworks.com
  • http://crl.paloaltonetworks.com  (TCP 80)
  • http://ocsp.godaddy.com  (TCP 80)
  • https://storage.googleapis.com
  • 34.90.244.133
  • 35.184.125.116

Required TCP ports:

  • TCP 444 and TCP 3978 (not necessary if you are using only device telemetry and do not have a Strata Logging Service license). 
  • For OCSP, you must also allow the firewalls to access ocsp.paloaltonetworks.com on port 80.
  • On firewalls running PAN-OS 9.1.7 or earlier, you also need a Security policy rule that allows SSL over port 444 to lic.lc.prod.us.cs.paloaltonetworks.com.
  • TCP 443, TCP 5222-5224, TCP 5228 and TCP 5229 (palo alto device-telemetry and google-base APP-IDS).

 

Region

Domain

UShttp://br-prd1.us.cdl.paloaltonetworks.com/
Europehttp://br-prd1.nl.cdl.paloaltonetworks.com/
UKhttp://br-prd1.uk.cdl.paloaltonetworks.com/
Canadahttp://br-prd1.ca1.ne1.cdl.paloaltonetworks.com/
Singaporehttp://br-prd1.sg1.se1.cdl.paloaltonetworks.com/
Japanhttp://br-prd1.jp1.ne1.cdl.paloaltonetworks.com/
Australiahttp://br-prd1.au1.se1.cdl.paloaltonetworks.com/
Germany http://br-prd1.de1.ew3.cdl.paloaltonetworks.com/
Indiahttp://br-prd1.in1.as1.cdl.paloaltonetworks.com/

 



Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XfqCCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail