AIOps Alert "Process Memory Depletion - Management Server"

AIOps Alert "Process Memory Depletion - Management Server"

6873
Created On 02/15/22 21:21 PM - Last Modified 03/27/23 21:05 PM


Symptom


  • Alert from AIOps regarding process memory depletion for "mgmtsrvr"


Environment


  • PAN-OS
  • AIOps Alert


Cause


A memory depletion in the "mgmtsrvr" process was found.



Resolution


If you receive this Alert, it is recommended to collect the following Troubleshooting Data below and open a Support Case. After data is collected, considering following the Mitigation Steps to bring down the memory usage of the mgmtsrvr process till Support can analyze the data. 

Troubleshooting Data

  1. Collect Tech Support File  (GUI: Device > Support  Click Generate Tech Support File)

  2. Generate a trace file using the following CLI command

debug software trace management-server

  1. Generate a core file using following command

debug software core management-server

  1. Collect the Device State (GUI: Device>Setup>Operations- Export: Export device state)
  2. Export the core file  (HOW TO EXPORT CORE FILES FROM A PALO ALTO NETWORKS DEVICE)
  3. Gather data below from AIOps
    1. Check the dates indicated by AIOps as to when the memory depletion started.
    2. Check if there were any config modifications, PANOS upgrades/downgrades, or any other changes performed around the time that might have triggered this behavior.
  4. (Optional) If performing Mitigation Steps below, collect another Tech Support File after completing steps
  5. Open a case with the above data.
     

Mitigation Steps

Till the issue is resolved, you can restart the mgmtsrvr process that to bring down the memory usage of management-server. 
NOTE: Recommended to be performed in a maintenance window


Potential Impact of restart the process:

  • After PAN-OS 10.1, mgmtsrvr on firewall serves as a message dispatcher(Similar to panorama), Backend daemons such as configd, distributord, iotd, logrcvr, pl-dlp_agent, reportd, and useridd will be restarted.
  • Prior to PAN-OS 10.1, following functionality on firewall will not be available during the process restart, 
    • UI and CLI access
    • HA Sync
    • Panorama push
    • Dynamic Updates
  • The mgmtsrvr on Panorama serves as a message dispatcher, All backend daemons are dependent on mgmtsrvr, when mgmtsrvr is restarted, all backend daemons will be restarted. Single access point to all the firewalls via proxy session on GUI.

Option 1 (Standalone Device)

  1. Save and export the candidate config.
  2. Save and export the current configuration.
  3. Perform a full commit
  4. Restart the management-server process using below command
debug software restart process management-server
  1. (For PAN-OS 10.0.X or 10.1.X) Restart the device-server to ensure that the commits go through without a problem. 
debug software restart process device-server

Option 2 (Device in Active/Passive HA)

  1. Disable "Preemptive" mode (GUI: Device > High Availability > General > Election Settings: Uncheck Preemptive )
  2. Failover to the passive device (From Active Device: Device > High Availability > Operations > Click Suspend local device)
  3. Restart the management-server from the CLI from the now Suspended device (debug software restart process management-server)
  4.  (For PAN-OS 10.0.X or 10.1.X) Restart the device-server to ensure that the commits go through without a problem. (debug software restart process device-server)
  5. From CLI run show management-clients to ensure that all processes have started successfully.
> show management-clients
              Client PRI    State Progress
-------------------------------------------------------------------------
            ha_agent  25     init        0
              sslmgr  10     init        0
               authd  10     init        0
             cryptod  10     init        0
              dagger  10     init        0    (op cmds only)
                cord  10     init        0
                logd  10     init        0    (op cmds only)
             reportd  10     init        0    (op cmds only)
             useridd  10     init        0
        distributord  10     init        0
                iotd  10     init        0
Overall status: init. Progress: 0
Warnings:
Errors:
NOTE: Restarting the process will temporarily mitigate the process growth, but the issue may re-surface.

 



Additional Information


PAN-175211 - Fixed a memory leak issue in the (mgmtsrvr) process. (Fixed on PAN-OS 9.0.16, 9.1.13, 10.0.9, 10.1.4)
PAN-183774 - Fixed an memory leak issue in the mgmtsrvr process, which resulted in an out-of-memory (OOM) condition and high availability (HA) failover. (Fixed on PANOS 9.1.13, 10.0.10, 10.1.5)


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oNBvCAM&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language