Device Telemetry failed to send file with error: Failed to send: file 'PA_XXXXXXXX-hr-interval_HOUR.tgz seen on system logs
11547
Created On 09/26/23 18:54 PM - Last Modified 10/04/23 02:32 AM
Symptom
- With Device Telemetry enabled, critical system logs (show log system) are generated when the firewall is not able to send files to the PaloAlto server
critical device- send-fa 0 Failed to send: file 'PA_00xxxxxx9_dt_10.1.10_20230926_0030_1-hr-interval_HOUR.tgz
- device_telemetry_send.log (less mp-log device_telemetry_send.log) display sending failure as shown below
497 dt_send INFO TX_FILE: dest server ip: xx.yy.zz.qq
497 dt_send INFO TX FILE: send_file_cmd: /usr/local/bin/dt_curl -i xx.yy.zz.qq -f /opt/panlogs/tmp/device_telemetry/hour/PA_00xxxxxx9_dt_10.1.10_20230926_0030_1-hr-interval_HOUR.tgz
002 dt_send INFO TX FILE: curl cmd status: 18, 18; err msg: 'Certificate Does Not Exist'
007 dt_send INFO update send failed count: resend_count: 43, update_count = 44
009 dt_send INFO update_tx_failed_count: failed send: set intvl resend-failed-count to 4
- Device certificate status shows no device certificate
> show device-certificate status
Device Certificate information:
No device certificate found
- Device telemetry setting shows device certificate does not exist
> show device-telemetry settings
Device Telemetry Settings:
device-health-performance: yes
product-usage: yes
threat-prevention: yes
region: Americas
status: Device Certificate does not exist
Environment
- Palo Alto Firewall or Panorama
- PAN-OS 10.1 or above
- Device Telemetry
Cause
This occurs when the firewall or panorama does not have a valid device certificate
Resolution
- Install and Fetch the valid device certificate for the Firewall.
- Refer Steps documented at Install a Device Certificate