Strata Logging Service Status Shows Error "Result: Customer is not provisioned in CSP" After Cloud Services Plugin Upgrade on Panorama

Strata Logging Service Status Shows Error "Result: Customer is not provisioned in CSP" After Cloud Services Plugin Upgrade on Panorama

1989
Created On 03/13/26 07:32 AM - Last Modified 05/14/26 18:35 PM


Symptom


  • Strata Logging Service (SLS) status displays an error after upgrading the Cloud Services plugin on Panorama.
    Navigation path: PANORAMA > Cloud Services > Status > Status tab > Strata Logging Service > details
    Navigation path: PANORAMA > Cloud Services > Status > Status tab > Strata Logging Service > details
  • lcaas_agent.log (> less mp-log lcaas_agent.log) displays the following errors and incorrect endpoint queries: 
    lcaas_agent INFO source interface: src route sysd str: cfg.net.s0.srcif
    lcaas_agent INFO source interface: src_table: {'refresh': 300}
    lcaas_agent INFO Server not passed in. Picking up from cfg.lcaas-orch-server-domain sysd node
    lcaas_agent INFO LCaas server port not passed in. Picking up from cfg.lcaas-orch-server-port sysd node
    lcaas_agent INFO Server-cert revocation check status: good
    lcaas_agent INFO URL=https://cdl-highgov1.us1.cent1.highgov.cdl.paloaltonetworks.com:444/Platform/CustomerInfo/
    lcaas_agent INFO CERT=/opt/pancfg/mgmt/ssl/private/device.crt
    lcaas_agent INFO response from orchestrator=b'{"code":401,"message":"Got error. No provisioned tenant id found for serial number in cert subject: ClientCert.Subject(commonName=<Serial Number>, orgUnit=null, serialNumber=null, oid=OID.1.3.6.1.4.1.25461.4.22.1)","timeStamp":"2026-03-04T18:04:08.577Z"}'
    lcaas_agent INFO Resp from cloud service : b'{"code":401,"message":"Got error. No provisioned tenant id found for serial number in cert subject: ClientCert.Subject(commonName=<Serial Number>, orgUnit=null, serialNumber=null, oid=OID.1.3.6.1.4.1.25461.4.22.1)","timeStamp":"2026-03-04T18:04:08.577Z"}'
    lcaas_agent ERROR Customer is not provisioned in CSP
  • sdb.txt in the Tech Support file (> show system state) displays the following parameter:
    cfg.lcaas-orch-server-domain: cdl-highgov1.us1.cent1.highgov.cdl.paloaltonetworks.com


Environment


  • Panorama
  • Cloud Services plugin versions prior to 5.1.0-h26
  • Strata Logging Service (SLS)


Cause


The Cloud Services plugin uses an incorrect endpoint (cdl-highgov1.us1.cent1.highgov.cdl.paloaltonetworks.com) to query customer information.



Resolution


  1. Log in to the Panorama CLI.
  2. Run the following command to update the endpoint value:
    debug plugins cloud_services set-lcaas-orch-server-domain lic.lc.prod.us.cs.paloaltonetworks.com
  3. Wait up to one hour for Panorama to fetch the customer information from the correct endpoint.
    Note: Panorama local commit is not required for this command to take effect.


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000oMK9KAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail