How to troubleshoot Log forwarding delay between Strata Logging Service and https log receiver
6966
Created On 12/05/24 19:13 PM - Last Modified 01/10/25 03:18 AM
Symptom
SLS admins / Https log receiver admins may observe small to significant delay while receiving logs on https log receiver. For example,
- Dashboard->Forwarding Log Rate graph may be showing unusual disconnects to indicate the latency
- admins may notice reduction in logs forwarded under Dashboard->Latency
Environment
- Prisma Access of NGFW Firewalls
- Strata Logging Service
Cause
- Intermittent TCP/SSL/TLS connection issues.
- Https log receiver may having slow speed performance issues which is causing the delay.
Resolution
Here are a few steps that can help troubleshoot the issue towards resolution
- On log forwarding profile, verify if “Test Connection” is a success. If its showing failure, there may be issues (1) network issues (2) certificate (3) intermittent connection issues of TCP/SSL/TLS.
- Check on the SLS >Dashboard graph to see if the logs are forwarded. This will give a high level overview on the lag.
- Ensure that SLS is receiving logs from the firewalls by checking SLS >Explore TAB. This should show logs in real time.
- Ensure that there are no connection errors in raw log of Https log receiver.