How to troubleshoot Log forwarding delay between Strata Logging Service and https log receiver

How to troubleshoot Log forwarding delay between Strata Logging Service and https log receiver

6966
Created On 12/05/24 19:13 PM - Last Modified 01/10/25 03:18 AM


Symptom


SLS admins / Https log receiver admins may observe small to significant delay while receiving logs on https log receiver. For example,

  • Dashboard->Forwarding Log Rate graph may be showing unusual disconnects to indicate the latency 
  • admins may notice reduction in logs forwarded under Dashboard->Latency

 



Environment


  • Prisma Access of NGFW Firewalls
  • Strata Logging Service


Cause


  • Intermittent TCP/SSL/TLS connection issues.
  • Https log receiver may having slow speed performance issues which is causing the delay.


Resolution


Here are a few steps that can help troubleshoot the issue towards resolution

  1. On log forwarding profile, verify if “Test Connection” is a success. If its showing failure, there may be issues (1) network issues (2) certificate (3) intermittent connection issues of TCP/SSL/TLS.
  2. Check on the SLS >Dashboard graph to see if the logs are forwarded. This will give a high level overview on the lag.
  3. Ensure that SLS is receiving logs from the firewalls by checking SLS >Explore TAB. This should show logs in real time. 
  4. Ensure that there are no connection errors in raw log of Https log receiver. 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sd4ZCAQ&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language