Technical Support File (TSF) – Data Content & Handling Statement

Technical Support File (TSF) – Data Content & Handling Statement

404
Created On 04/14/26 08:45 AM - Last Modified 05/18/26 15:37 PM


Environment


Any platform, virtual or physical, that runs PAN-OS software



Resolution


1. TSF Generation

Generation of the TSF is a privileged action restricted to administrators with Superuser access rights within the PAN-OS Role-Based Access Control (RBAC) system.

 

2. Data Composition

The TSF aggregates data from the Management Plane (MP) and Data Plane (DP) into four primary categories:

 

2.1 Device Configuration (State Data)

The file includes a complete "snapshot" of the device settings required to replicate the logical environment.

  • Configuration Files: running-config.xml (local firewall) or merged-running-config.xml (Panorama-managed). This includes Security Policies, NAT rules, Network Interfaces, and Object definitions.
  • Hardware Identity: Serial numbers, model revision, and license information.
  • Authentication Profiles: Configuration settings for RADIUS, LDAP, or SAML profiles (Note: See Section 3 for credential sanitization).

 

2.2 System and Daemon Logs (Operational Data)

These logs track the health of internal background processes ("daemons"). 

  • Management Plane Logs: Process logs from the daemons running on the management plane. Some examples include ms.log (Management Server), devsrvr.log (Device Server), authd.log (Authentication daemon), ha_agent.log (daemon tracking HA states and transitions), etc.
    • There are logs that periodically collect management plane resource utilization in the files mp-monitor.log[.X] files.
  • Dataplane Logs: Process logs from the daemons running on the dataplane. Some examples include brdagent.log (daemon responsible for managing interfaces and internal components), pan_dha.log (managing dataplane HA transitions), pan_task_XX.log (daemons responsible for packet processing), etc.
    • There are logs that periodically collect management plane resource utilization in the files dp-monitor.log[.X] files.
  • System Logs: Records of general system events such as reboots, process restarts, link state changes, and hardware alerts.

 

2.3 Resource Utilization and Performance

  • System Resources: Snapshots of CPU load, memory usage, disk space utilization, dataplane performance indicators (dataplane CPU load, packet buffer utilization) - mp-monitor.log, dp-monitor.log.
  • Interface Statistics: Global counters for throughput, packet drops, and interface errors.
  • Routing: The current Routing Information Base (RIB) and Forwarding Information Base (FIB).
  • Session State Tables: Metadata regarding active network flows, including Source IP, Destination IP, Destination Port, and Protocol. Note: This is strictly flow metadata; it does not include application layer payload.

 

2.4 Critical Diagnostics

  • Core Dumps: If a system process has crashed, a "backtrace" summary is included to identify the code responsible for the crash.
    • In certain scenarios where the packet processing daemon on the dataplane crashes (all_pktproc), in addition to the backtrace file, a single packet would also be saved. That is the packet that was being processed by the daemon at the time when it crashed.
  • CLI History: A log of recent Command Line Interface commands executed by administrators (used to correlate manual changes with system issues).

 

3. Privacy and Security Controls

Palo Alto Networks enforces strict data minimization principles regarding TSF generation.

3.1 Automated Credential Sanitization

During TSF generation, the system executes a mandatory scrubbing script. This process:

  • Removes Private Keys: SSL/TLS private keys and SSH host keys are stripped.
  • Removes Passwords: Passwords and Pre-Shared Keys (PSKs) are removed or hashed.
  • Removes Secrets: RADIUS/TACACS+ secrets are removed.

 

3.2 Exclusion of User Traffic Payload

The TSF does not contain network traffic payload.

  • It does not contain the contents of emails, files, web pages, or database transactions passing through the firewall.
  • It does not contain packet captures (PCAP) *(see section 2.4 describing the only exception to this).

 

3.3 Exclusion of Traffic Logs

The TSF does not include Traffic, Threat, or URL Filtering logs.

 

3.4 Retention of Network Topology Indicators

While authentication credentials are strictly sanitized, the TSF retains network architecture data necessary for troubleshooting. This includes:

  • IP Addresses: Network Layer (L3) addresses for interfaces, gateways, and objects.
  • Hostnames: Device names and FQDNs defined in the configuration.
  • Object Names: Custom labels used for servers or user groups (e.g., "HQ-Server-Pool").

 

4. Customer Verification

The TSF is a standard GZIP-compressed TAR archive (.tgz). Customers may verify the contents of the file prior to upload by opening the archive with standard tools (e.g., 7-Zip, WinRAR, or tar) to inspect the file structure and contents directly.

 



Additional Information


References

GCS (Global Customer Services) Privacy Datasheet, Describes how Support Team handles data (including TSFs) for troubleshooting. 

How to Generate and Upload a Tech Support File Using the WebGUI and CLI, KB article



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wkwbKAA&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail