Strata Logging Service Status Shows Error "Result: Customer is not provisioned in CSP" After Cloud Services Plugin Upgrade on Panorama
1989
Created On 03/13/26 07:32 AM - Last Modified 05/14/26 18:35 PM
Symptom
- Strata Logging Service (SLS) status displays an error after upgrading the Cloud Services plugin on Panorama.
Navigation path: PANORAMA > Cloud Services > Status > Status tab > Strata Logging Service > details - lcaas_agent.log (> less mp-log lcaas_agent.log) displays the following errors and incorrect endpoint queries:
lcaas_agent INFO source interface: src route sysd str: cfg.net.s0.srcif lcaas_agent INFO source interface: src_table: {'refresh': 300} lcaas_agent INFO Server not passed in. Picking up from cfg.lcaas-orch-server-domain sysd node lcaas_agent INFO LCaas server port not passed in. Picking up from cfg.lcaas-orch-server-port sysd node lcaas_agent INFO Server-cert revocation check status: good lcaas_agent INFO URL=https://cdl-highgov1.us1.cent1.highgov.cdl.paloaltonetworks.com:444/Platform/CustomerInfo/ lcaas_agent INFO CERT=/opt/pancfg/mgmt/ssl/private/device.crt lcaas_agent INFO response from orchestrator=b'{"code":401,"message":"Got error. No provisioned tenant id found for serial number in cert subject: ClientCert.Subject(commonName=<Serial Number>, orgUnit=null, serialNumber=null, oid=OID.1.3.6.1.4.1.25461.4.22.1)","timeStamp":"2026-03-04T18:04:08.577Z"}' lcaas_agent INFO Resp from cloud service : b'{"code":401,"message":"Got error. No provisioned tenant id found for serial number in cert subject: ClientCert.Subject(commonName=<Serial Number>, orgUnit=null, serialNumber=null, oid=OID.1.3.6.1.4.1.25461.4.22.1)","timeStamp":"2026-03-04T18:04:08.577Z"}' lcaas_agent ERROR Customer is not provisioned in CSP - sdb.txt in the Tech Support file (> show system state) displays the following parameter:
cfg.lcaas-orch-server-domain: cdl-highgov1.us1.cent1.highgov.cdl.paloaltonetworks.com
Environment
- Panorama
- Cloud Services plugin versions prior to 5.1.0-h26
- Strata Logging Service (SLS)
Cause
The Cloud Services plugin uses an incorrect endpoint (cdl-highgov1.us1.cent1.highgov.cdl.paloaltonetworks.com) to query customer information.
Resolution
- Log in to the Panorama CLI.
- Run the following command to update the endpoint value:
debug plugins cloud_services set-lcaas-orch-server-domain lic.lc.prod.us.cs.paloaltonetworks.com - Wait up to one hour for Panorama to fetch the customer information from the correct endpoint.
Note: Panorama local commit is not required for this command to take effect.
Additional Information
- CYR-44598 is fixed in Cloud Services plugin 5.1.0-h26 or later.
- 5.1 Release Notes