Docy

OPLP Alerts and Event Descriptions

OPLP Alerts and Event Descriptions

This document provides a complete list of OPLP alerts, their description, the required user action, and the SNMP trap notifications that the appliance generates when SNMP traps are enabled.

Alerts with a priority “None” are recovery alerts. “Medium” priority alerts are warnings and “High” priority alerts are critical.

AlertPriorityDescriptionUser ActionSNMP Trap Notification
Device_rebootedNoneDevice was rebooted.Check the status of services by running show service-statusdeviceRebootedNotif
Device_rebootedHighDevice rebooted.Check the status of services by running show service-statusdeviceRebootedNotif
Storage-root-partitionNoneDisk usage of the root partition is below 75%.Check the available disk size of the root partition.
From the Linux shell, run the command: df -h
storageRootNotif
Storage-root-partitionMediumDisk usage of the root partition is at 75% or more.Check the available disk size of the root partition.
From the Linux shell, run the command: df -h
storageRootNotif
Storage-root-partitionHighDisk usage of the root partition is at 90% or more.Check the available disk size of the root partition.
From the Linux shell, run the command: df -h
storageRootNotif
Storage-securestore-partitionNoneSecure Store disk usage is below 75%.Check the available disk size of the Secure Store disk using the “df” command.
To increase the size of the partition contact support.
Storage-securestore-partitionMediumSecure Store disk usage is is at 75% or more.Check the available disk size of the Secure Store disk using the “df” command.
To increase the size of the partition contact support.
Storage-securestore-partitionHighSecure Store disk usage is is at 90% or more.Check the available disk size of the Secure Store disk using the “df” command.
To increase the size of the partition contact support.
Storage-lcmysql- partitionNoneDisk usage of lcmysql is below 75%.Check the available disk size of the lcmysql partition using the “df” command.
To increase the size of the partition contact support.
storageMysqlNotif
Storage-lcmysql- partitionMediumDisk usage of lcmysql is at 75% or more.Check the available disk size of the lcmysql partition using the “df” command.
To increase the size of the partition contact support.
storageMysqlNotif
Storage-lcmysql- partitionHighDisk usage of lcmysql is at 90% or more.Check the available disk size of the lcmysql partition using the “df” command.
To increase the size of the partition contact support.
storageMysqlNotif
Storage-lcmongo- infrastructure- partitionNoneDisk usage of lcmongo-infrastructure is below 75%.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
To increase the size of the partition contact support.
storageMongoInfraNotif
Storage-lcmongo- infrastructure- partitionMediumDisk usage of lcmongo-infrastructure is at 75% or more.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
To increase the size of the partition contact support.
storageMongoInfraNotif
Storage-lcmongo- infrastructure- partitionHighDisk usage of lcmongo-infrastructure is is at 90% or more.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
To increase the size of the partition contact support.
storageMongoInfraNotif
Storage-lclw-partitionNoneDisk usage of lclw is below 75%.Check the available disk size of the lclw partition using the “df” command.
If required, increase the disk partition using the command
troubleshooting expand-partition log
storageLogNotif
Storage-lclw-partitionMediumDisk usage of lclw is at 75% or more.Check the available disk size of the lclw partition using the “df” command.
If required, increase the disk partition using the command
troubleshooting expand-partition log
storageLogNotif
Storage-lclw-partitionHighDisk usage of lclw is at 90% or more.Check the available disk size of the lclw partition using the “df” command.
If required, increase the disk partition using the command
troubleshooting expand-partition log
storageLogNotif
Storage-lckafkabroker- partitionNoneDisk usage of lckafkabroker is below 75%.Check the available disk size of the lckafkabroker partition using the “df” command.
To increase the size of the partition contact support.
storageKafkaBrokerNotif
Storage-lckafkabroker- partitionMediumDisk usage of lckafkabroker is at 75% or more.Check the available disk size of the lckafkabroker partition using the “df” command.
To increase the size of the partition contact support.
storageKafkaBrokerNotif
Storage-lckafkabroker- partitionHighDisk usage of lckafkabroker is at 90% or more.Check the available disk size of the lckafkabroker partition using the “df” command.
To increase the size of the partition contact support.
storageKafkaBrokerNotif
Storage-lcmongo-event- partitionNoneDisk usage of lcmongo-event is below 75%.Check the available disk size of the lcmongo-event partition using the “df” command.
To increase the size of the partition contact support.
storageMongoEventNotif
Storage-lcmongo-event- partitionMediumDisk usage of lcmongo-event is at 75% or more.Check the available disk size of the lcmongo-event partition using the “df” command.
To increase the size of the partition contact support.
storageMongoEventNotif
Storage-lcmongo-event- partitionHighDisk usage of lcmongo-event is at 90% or more.Check the available disk size of the lcmongo-event partition using the “df” command.
To increase the size of the partition contact support.
storageMongoEventNotif
Reportjob_worker_statusNoneReportjob worker is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobWorkerNotif
Reportjob_worker_statusHighReportjob worker is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobWorkerNotif
Reportjob_scheduler_ statusNoneReportjob scheduler is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobSchedulerNotif
Reportjob_scheduler_ statusHighReportjob scheduler is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
reportjobSchedulerNotif
Cfgagent_connectionNoneCfgagent connection to config service has been restored.If cfgagent is not connected to config services, then check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
cfgagentConnectionNotif
MySql_statusNoneMySql db is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mysqlNotif
MySql_statusHighMySql db is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mysqlNotif
Event_flow_from_deviceNoneEvent flow from device has been restored.Indicates if the number of events coming in from a device for a particular week is half the number of events received during the previous week.
Check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
eventflowNotif
Event_flow_from_deviceHighEvent flow from the device is affected.Indicates if the number of events coming in from a device for a particular week is half the number of events received during the previous week.
Check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
eventflowNotif
Files_not_uploaded_24_ hrsNoneFiles uploaded successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded24hNotif
Files_not_uploaded_24_ hrsHighAt least 5 files were not uploaded within 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded24hNotif
Files_not_uploaded_48_ hrsNoneFiles uploaded successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded48hNotif
Files_not_uploaded_48_ hrsHighAt least 1 file was not uploaded within 48 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotUploaded48hNotif
Files_not_picked_up_24_ hrsNoneFiles picked up for processing successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked24hNotif
Files_not_picked_up_24_ hrsHighAt least 5 files were not picked up for processing within 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked24hNotif
Files_not_picked_up_48_ hrsNoneFiles picked up for processing successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked48hNotif
Files_not_picked_up_48_ hrsHighAt least 1 file was not picked up for processing within 48 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
filesNotPicked48hNotif
Queryservice_statusNoneQueryservice is running.Run the command restart queryservice to restart the servicequeryServiceStatusNotif
Queryservice_statusHighQueryservice is not running.Run the command restart queryservice to restart the servicequeryServiceStatusNotif
Mongos_statusNoneMongos is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoSStatusNotif
Mongos_statusHighMongos is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoSStatusNotif
Mongodb_statusNoneMongodb is running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoDBStatusNotif
Mongodb_statusHighMongodb is not running.Contact support and provide them the debug package.
Run:
troubleshooting debug-package generate
mongoDBStatusNotif
Threat_feed_ageNoneThe threat feed data on the device is up-to-date.threatfeedAgeNotif
Auth_proxy_statusNoneAuth Proxy services have recovered.Contact support to resolve this issue.authProxyStatusNotif
Auth_proxy_statusHighAuth Proxy services are down. Users may not be able to login to Microsoft Office 365.Contact support to resolve this issue.authProxyStatusNotif
No_events_from_deviceNoneEvents from device were successfully sent.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noEventsFromDeviceNotif
No_events_from_deviceHighEvents from device not received in the last 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noEventsFromDeviceNotif
No_metrics_from_deviceNoneMetrics from device were successfully sent.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noMetricsFromDeviceNotif
No_metrics_from_deviceMediumMetrics from device were not received in the last 3 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noMetricsFromDeviceNotif
No_metrics_from_deviceHighMetrics from device were not received in the last 6 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
noMetricsFromDeviceNotif
Storage-1aNoneDisk usage of /nslogs is below 50%.Check the available disk size of the /nslogs partition using the status all command.
To increase the size of the partition contact support.
Storage-1aMediumDisk usage of /nslogs is at 50% or more.Check the available disk size of the /nslogs partition using the status all command.
To increase the size of the partition contact support.
Storage-1aHighDisk usage of /nslogs is at 75% or more.Check the available disk size of the /nslogs partition using the status all command.
To increase the size of the partition contact support.
Log_Process-4NoneFiles were picked up.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-4MediumFiles were not being picked within 10 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-4HighFiles were not being picked within 15 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5aNoneFiles moved and split successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5aMediumFiles moved but not split within 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5aHighFiles moved but not split within 72 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5bNoneFiles moved & split and parsed successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5bMediumFiles moved & split, parsing not finished in 24 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5bHighFiles moved & split, parsing not finished in 72 hours.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5cNoneFile parsing finished; events uploaded successfully.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5cMediumFile parsing finished; events haven't been uploaded within 24 hours of parsing.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Log_Process-5cHighFile parsing finished; events haven't been uploaded within 72 hours of parsing done.Run the following command to see the list of unprocessed files:
log-upload tools list
If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
For a complete list of supported tenant domains, see Outbound Ports.
Contact support to resolve this issue.
Callhome_statusNoneCallhome endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.callhomeConnectivityNotif
Callhome_statusHighCallhome endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.callhomeConnectivityNotif
Downloader_statusNoneDownloader endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.downloaderConnectivityNotif
Downloader_statusHighDownloader endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.downloaderConnectivityNotif
Config_service_statusNoneConfig service endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.configsvcConnectivityNotif
Config_service_statusHighConfig service endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.configsvcConnectivityNotif
UI_hostname_statusNoneHTTP endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.uihostnameConnectivityNotif
UI_hostname_statusHighHTTP endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.uihostnameConnectivityNotif
UI_hostname_ssh_statusNoneSSH endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.uihostnamesshConnectivityNotif
UI_hostname_ssh_statusHighSSH endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.uihostnamesshConnectivityNotif
Logupload_statusNoneLogupload endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.loguploadConnectivityNotif
Logupload_statusHighLogupload endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.loguploadConnectivityNotif

Outboard Ports

Use these ports for management connectivity and log uploads.

For management connectivity:

Domain DescriptionPort
config-<tenant-URL>Use for configuration updates. The domain needs to be SSL allowlisted if you have SSL decryption enabled. 443
download-<tenant-URL>Use for software upgrades. 443
messenger-<tenant-URL> Use for reporting and status updates in the UI. The domain needs to be SSL allowlisted if you have SSL decryption enabled.443
callhome-<tenant-URL> Use for receiving metrics from on-premises appliances and forwarding them to cloud tenants, as well as receiving event data from an on-premises dataplane appliances. Also for receiving custom user attributes from user endpoints. The domain needs to be SSL allowlisted if you have SSL decryption enabled.443

For log uploads:

DomainDescription Port
upload-<tenant-URL>Use for sending logs to the Netskope cloud with SFTP. This is the default port for log uploads. 22
logupload-<tenant-URL>Use for sending logs to the Netskope cloud with HTTPS. This port is enabled by default. 443
<tenant-URL> Use for fetching the REST API token with HTTPS. 443
Share this Doc
In this topic ...