Docy

OPLP Alerts and Event Descriptions

OPLP Alerts and Event Descriptions

This document provides a complete list of OPLP alerts, their description, the required user action, and the SNMP trap notifications that the appliance generates when SNMP traps are enabled.

Alerts with a priority “None” are recovery alerts. “Medium” priority alerts are warnings and “High” priority alerts are critical.

AlertPriorityDescriptionUser ActionSNMP Trap Notification
Device_rebootedNoneDevice was rebooted.Check the status of services by running show service-statusdeviceRebootedNotif
Device_rebootedHighDevice rebooted.Check the status of services by running show service-statusdeviceRebootedNotif
Storage-root-partitionNoneDisk usage of the root partition is below 75%.Check the available disk size of the root partition.
From the Linux shell, run the command: df -h
storageRootNotif
Storage-root-partitionMediumDisk usage of the root partition is at 75% or more.Check the available disk size of the root partition.
From the Linux shell, run the command: df -h
storageRootNotif
Storage-root-partitionHighDisk usage of the root partition is at 90% or more.Check the available disk size of the root partition.
From the Linux shell, run the command: df -h
storageRootNotif
Storage-securestore-partitionNoneSecure Store disk usage is below 75%.Check the available disk size of the Secure Store disk using the “df” command.
To increase the size of the partition contact support.
Storage-securestore-partitionMediumSecure Store disk usage is is at 75% or more.Check the available disk size of the Secure Store disk using the “df” command.
To increase the size of the partition contact support.
Storage-securestore-partitionHighSecure Store disk usage is is at 90% or more.Check the available disk size of the Secure Store disk using the “df” command.
To increase the size of the partition contact support.
Storage-lcmysql- partitionNoneDisk usage of lcmysql is below 75%.Check the available disk size of the lcmysql partition using the “df” command.
To increase the size of the partition contact support.
storageMysqlNotif
Storage-lcmysql- partitionMediumDisk usage of lcmysql is at 75% or more.Check the available disk size of the lcmysql partition using the “df” command.
To increase the size of the partition contact support.
storageMysqlNotif
Storage-lcmysql- partitionHighDisk usage of lcmysql is at 90% or more.Check the available disk size of the lcmysql partition using the “df” command.
To increase the size of the partition contact support.
storageMysqlNotif
Storage-lcmongo- infrastructure- partitionNoneDisk usage of lcmongo-infrastructure is below 75%.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
To increase the size of the partition contact support.
storageMongoInfraNotif
Storage-lcmongo- infrastructure- partitionMediumDisk usage of lcmongo-infrastructure is at 75% or more.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
To increase the size of the partition contact support.
storageMongoInfraNotif
Storage-lcmongo- infrastructure- partitionHighDisk usage of lcmongo-infrastructure is is at 90% or more.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
To increase the size of the partition contact support.
storageMongoInfraNotif
Storage-lclw-partitionNoneDisk usage of lclw is below 75%.Check the available disk size of the lclw partition using the “df” command.
If required, increase the disk partition using the command
troubleshooting expand-partition log
storageLogNotif
Storage-lclw-partitionMediumDisk usage of lclw is at 75% or more.Check the available disk size of the lclw partition using the “df” command.
If required, increase the disk partition using the command
troubleshooting expand-partition log
storageLogNotif
Storage-lclw-partitionHighDisk usage of lclw is at 90% or more.Check the available disk size of the lclw partition using the “df” command.
If required, increase the disk partition using the command
troubleshooting expand-partition log
storageLogNotif
Storage-lckafkabroker- partitionNoneDisk usage of lckafkabroker is below 75%.Check the available disk size of the lckafkabroker partition using the “df” command.
To increase the size of the partition contact support.
storageKafkaBrokerNotif
Storage-lckafkabroker- partitionMediumDisk usage of lckafkabroker is at 75% or more.Check the available disk size of the lckafkabroker partition using the “df” command.
To increase the size of the partition contact support.
storageKafkaBrokerNotif
Storage-lckafkabroker- partitionHighDisk usage of lckafkabroker is at 90% or more.Check the available disk size of the lckafkabroker partition using the “df” command.
To increase the size of the partition contact support.
storageKafkaBrokerNotif
Storage-lcmongo-event- partitionNoneDisk usage of lcmongo-event is below 75%.Check the available disk size of the lcmongo-event partition using the “df” command.
To increase the size of the partition contact support.
storageMongoEventNotif
Storage-lcmongo-event- partitionMediumDisk usage of lcmongo-event is at 75% or more.Check the available disk size of the lcmongo-event partition using the “df” command.
To increase the size of the partition contact support.
storageMongoEventNotif
Storage-lcmongo-event- partitionHighDisk usage of lcmongo-event is at 90% or more.Check the available disk size of the lcmongo-event partition using the “df” command.
To increase the size of the partition contact support.
storageMongoEventNotif
Reportjob_worker_statusNoneReportjob worker is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobWorkerNotif
Reportjob_worker_statusHighReportjob worker is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobWorkerNotif
Reportjob_scheduler_ statusNoneReportjob scheduler is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobSchedulerNotif
Reportjob_scheduler_ statusHighReportjob scheduler is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobSchedulerNotif
Cfgagent_connectionNoneCfgagent connection to config service has been restored.If cfgagent is not connected to config services, then check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
cfgagentConnectionNotif
MySql_statusNoneMySql db is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mysqlNotif
MySql_statusHighMySql db is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mysqlNotif
Event_flow_from_deviceNoneEvent flow from device has been restored.Indicates if the number of events coming in from a device for a particular week is half the number of events received during the previous week.
Check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
eventflowNotif
Event_flow_from_deviceHighEvent flow from the device is affected.Indicates if the number of events coming in from a device for a particular week is half the number of events received during the previous week.
Check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
eventflowNotif
Files_not_uploaded_24_ hrsNoneFiles uploaded successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded24hNotif
Files_not_uploaded_24_ hrsHighAt least 5 files were not uploaded within 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded24hNotif
Files_not_uploaded_48_ hrsNoneFiles uploaded successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded48hNotif
Files_not_uploaded_48_ hrsHighAt least 1 file was not uploaded within 48 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded48hNotif
Files_not_picked_up_24_ hrsNoneFiles picked up for processing successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked24hNotif
Files_not_picked_up_24_ hrsHighAt least 5 files were not picked up for processing within 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked24hNotif
Files_not_picked_up_48_ hrsNoneFiles picked up for processing successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked48hNotif
Files_not_picked_up_48_ hrsHighAt least 1 file was not picked up for processing within 48 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked48hNotif
Queryservice_statusNoneQueryservice is running.Run the command restart queryservice to restart the servicequeryServiceStatusNotif
Queryservice_statusHighQueryservice is not running.Run the command restart queryservice to restart the servicequeryServiceStatusNotif
Mongos_statusNoneMongos is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoSStatusNotif
Mongos_statusHighMongos is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoSStatusNotif
Mongodb_statusNoneMongodb is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoDBStatusNotif
Mongodb_statusHighMongodb is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoDBStatusNotif
Threat_feed_ageNoneThe threat feed data on the device is up-to-date.threatfeedAgeNotif
Auth_proxy_statusNoneAuth Proxy services have recovered.Contact support to resolve this issue.authProxyStatusNotif
Auth_proxy_statusHighAuth Proxy services are down. Users may not be able to login to Microsoft Office 365.Contact support to resolve this issue.authProxyStatusNotif
No_events_from_deviceNoneEvents from device were successfully sent.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noEventsFromDeviceNotif
No_events_from_deviceHighEvents from device not received in the last 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noEventsFromDeviceNotif
No_metrics_from_deviceNoneMetrics from device were successfully sent.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noMetricsFromDeviceNotif
No_metrics_from_deviceMediumMetrics from device were not received in the last 3 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noMetricsFromDeviceNotif
No_metrics_from_deviceHighMetrics from device were not received in the last 6 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noMetricsFromDeviceNotif
Storage-1aNoneDisk usage of /nslogs is below 50%.Check the available disk size of the /nslogs partition using the status all command.
To increase the size of the partition contact support.
Storage-1aMediumDisk usage of /nslogs is at 50% or more.Check the available disk size of the /nslogs partition using the status all command.
To increase the size of the partition contact support.
Storage-1aHighDisk usage of /nslogs is at 75% or more.Check the available disk size of the /nslogs partition using the status all command.
To increase the size of the partition contact support.
Log_Process-4NoneFiles were picked up.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-4MediumFiles were not being picked within 10 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-4HighFiles were not being picked within 15 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5aNoneFiles moved and split successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5aMediumFiles moved but not split within 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5aHighFiles moved but not split within 72 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5bNoneFiles moved & split and parsed successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5bMediumFiles moved & split, parsing not finished in 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5bHighFiles moved & split, parsing not finished in 72 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5cNoneFile parsing finished; events uploaded successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5cMediumFile parsing finished; events haven't been uploaded within 24 hours of parsing.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5cHighFile parsing finished; events haven't been uploaded within 72 hours of parsing done.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Callhome_statusNoneCallhome endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.callhomeConnectivityNotif
Callhome_statusHighCallhome endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.callhomeConnectivityNotif
Downloader_statusNoneDownloader endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.downloaderConnectivityNotif
Downloader_statusHighDownloader endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.downloaderConnectivityNotif
Config_service_statusNoneConfig service endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.configsvcConnectivityNotif
Config_service_statusHighConfig service endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.configsvcConnectivityNotif
UI_hostname_statusNoneHTTP endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.uihostnameConnectivityNotif
UI_hostname_statusHighHTTP endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.uihostnameConnectivityNotif
UI_hostname_ssh_statusNoneSSH endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.uihostnamesshConnectivityNotif
UI_hostname_ssh_statusHighSSH endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.uihostnamesshConnectivityNotif
Logupload_statusNoneLogupload endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.loguploadConnectivityNotif
Logupload_statusHighLogupload endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.loguploadConnectivityNotif

Outboard Ports

Use these ports for management connectivity and log uploads.

Note

In release 46 domain names changed. Using version 46 and later requires using the new domainnames. Existing deployments (release 45 and prior) do not require the new domain names, but using them are recommended. The one required update is forauto-updates; either turn off auto-update or use the new download-<tenant hostname>.goskope.com domain name. New deployments with release 46 and higher do need to use the new domain names.

For management connectivity:

Domain DescriptionPort
New:config-<tenant hostname>.goskope.com

Old: config.goskope.com

Use for configuration updates. The domain needs to be SSL allowlisted if you have SSL decryption enabled. 443
New: download-<tenant hostname>.goskope.com

Old: download.goskope.com

Use for software upgrades. 443
New: messenger-<tenant hostname>.goskope.com

Old: messenger.goskope.com

Use for reporting and status updates in the UI. The domain needs to be SSL allowlisted if you have SSL decryption enabled.443
New: callhome-<tenant hostname>.goskope.com

Old: callhome.goskope.com

Use for receiving metrics from on-premises appliances and forwarding them to cloud tenants, as well as receiving event data from an on-premises dataplane appliances. Also for receiving custom user attributes from user endpoints. The domain needs to be SSL allowlisted if you have SSL decryption enabled.443

Note

For international deployments, use ~ -<tenant hostname>.eu.goskope.com or ~ -<tenant hostname>.de.goskope.com.

For log uploads:

DomainDescription Port
New: upload-<tenant hostname>.goskope.com

Old: upload.goskope.com

Use for sending logs to the Netskope cloud with SFTP. This is the default port for log uploads. 22
No change: logupload-<tenant hostname>.goskope.comUse for sending logs to the Netskope cloud with HTTPS. This port is enabled by default. 443
No change: <tenant hostname>.goskope.com Use for fetching the REST API token with HTTPS. 443

Note

For international deployments, use ~ -<tenant hostname>.eu.goskope.com or ~ -<tenant hostname>.de.goskope.com.

Share this Doc
In this topic ...