Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Appliances
    OPLP Alerts and Event Descriptions

    OPLP Alerts and Event Descriptions

    This document provides a complete list of OPLP alerts, their description, the required user action, and the SNMP trap notifications that the appliance generates when SNMP traps are enabled.

    Alerts with a priority “None” are recovery alerts. “Medium” priority alerts are warnings and “High” priority alerts are critical.

    AlertPriorityDescriptionUser ActionSNMP Trap Notification
    Device_rebootedNoneDevice was rebooted.Check the status of services by running show service-statusdeviceRebootedNotif
    Device_rebootedHighDevice rebooted.Check the status of services by running show service-statusdeviceRebootedNotif
    Storage-root-partitionNoneDisk usage of the root partition is below 75%.Check the available disk size of the root partition.
    From the Linux shell, run the command: df -h
    storageRootNotif
    Storage-root-partitionMediumDisk usage of the root partition is at 75% or more.Check the available disk size of the root partition.
    From the Linux shell, run the command: df -h
    storageRootNotif
    Storage-root-partitionHighDisk usage of the root partition is at 90% or more.Check the available disk size of the root partition.
    From the Linux shell, run the command: df -h
    storageRootNotif
    Storage-securestore-partitionNoneSecure Store disk usage is below 75%.Check the available disk size of the Secure Store disk using the “df” command.
    To increase the size of the partition contact support.
    Storage-securestore-partitionMediumSecure Store disk usage is is at 75% or more.Check the available disk size of the Secure Store disk using the “df” command.
    To increase the size of the partition contact support.
    Storage-securestore-partitionHighSecure Store disk usage is is at 90% or more.Check the available disk size of the Secure Store disk using the “df” command.
    To increase the size of the partition contact support.
    Storage-lcmysql- partitionNoneDisk usage of lcmysql is below 75%.Check the available disk size of the lcmysql partition using the “df” command.
    To increase the size of the partition contact support.
    storageMysqlNotif
    Storage-lcmysql- partitionMediumDisk usage of lcmysql is at 75% or more.Check the available disk size of the lcmysql partition using the “df” command.
    To increase the size of the partition contact support.
    storageMysqlNotif
    Storage-lcmysql- partitionHighDisk usage of lcmysql is at 90% or more.Check the available disk size of the lcmysql partition using the “df” command.
    To increase the size of the partition contact support.
    storageMysqlNotif
    Storage-lcmongo- infrastructure- partitionNoneDisk usage of lcmongo-infrastructure is below 75%.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
    To increase the size of the partition contact support.
    storageMongoInfraNotif
    Storage-lcmongo- infrastructure- partitionMediumDisk usage of lcmongo-infrastructure is at 75% or more.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
    To increase the size of the partition contact support.
    storageMongoInfraNotif
    Storage-lcmongo- infrastructure- partitionHighDisk usage of lcmongo-infrastructure is is at 90% or more.Check the available disk size of the lcmongo-infrastructure partition using the “df” command.
    To increase the size of the partition contact support.
    storageMongoInfraNotif
    Storage-lclw-partitionNoneDisk usage of lclw is below 75%.Check the available disk size of the lclw partition using the “df” command.
    If required, increase the disk partition using the command
    troubleshooting expand-partition log
    storageLogNotif
    Storage-lclw-partitionMediumDisk usage of lclw is at 75% or more.Check the available disk size of the lclw partition using the “df” command.
    If required, increase the disk partition using the command
    troubleshooting expand-partition log
    storageLogNotif
    Storage-lclw-partitionHighDisk usage of lclw is at 90% or more.Check the available disk size of the lclw partition using the “df” command.
    If required, increase the disk partition using the command
    troubleshooting expand-partition log
    storageLogNotif
    Storage-lckafkabroker- partitionNoneDisk usage of lckafkabroker is below 75%.Check the available disk size of the lckafkabroker partition using the “df” command.
    To increase the size of the partition contact support.
    storageKafkaBrokerNotif
    Storage-lckafkabroker- partitionMediumDisk usage of lckafkabroker is at 75% or more.Check the available disk size of the lckafkabroker partition using the “df” command.
    To increase the size of the partition contact support.
    storageKafkaBrokerNotif
    Storage-lckafkabroker- partitionHighDisk usage of lckafkabroker is at 90% or more.Check the available disk size of the lckafkabroker partition using the “df” command.
    To increase the size of the partition contact support.
    storageKafkaBrokerNotif
    Storage-lcmongo-event- partitionNoneDisk usage of lcmongo-event is below 75%.Check the available disk size of the lcmongo-event partition using the “df” command.
    To increase the size of the partition contact support.
    storageMongoEventNotif
    Storage-lcmongo-event- partitionMediumDisk usage of lcmongo-event is at 75% or more.Check the available disk size of the lcmongo-event partition using the “df” command.
    To increase the size of the partition contact support.
    storageMongoEventNotif
    Storage-lcmongo-event- partitionHighDisk usage of lcmongo-event is at 90% or more.Check the available disk size of the lcmongo-event partition using the “df” command.
    To increase the size of the partition contact support.
    storageMongoEventNotif
    Reportjob_worker_statusNoneReportjob worker is running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    reportjobWorkerNotif
    Reportjob_worker_statusHighReportjob worker is not running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    reportjobWorkerNotif
    Reportjob_scheduler_ statusNoneReportjob scheduler is running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    reportjobSchedulerNotif
    Reportjob_scheduler_ statusHighReportjob scheduler is not running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    reportjobSchedulerNotif
    Cfgagent_connectionNoneCfgagent connection to config service has been restored.If cfgagent is not connected to config services, then check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    cfgagentConnectionNotif
    MySql_statusNoneMySql db is running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    mysqlNotif
    MySql_statusHighMySql db is not running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    mysqlNotif
    Event_flow_from_deviceNoneEvent flow from device has been restored.Indicates if the number of events coming in from a device for a particular week is half the number of events received during the previous week.
    Check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    eventflowNotif
    Event_flow_from_deviceHighEvent flow from the device is affected.Indicates if the number of events coming in from a device for a particular week is half the number of events received during the previous week.
    Check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    eventflowNotif
    Files_not_uploaded_24_ hrsNoneFiles uploaded successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotUploaded24hNotif
    Files_not_uploaded_24_ hrsHighAt least 5 files were not uploaded within 24 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotUploaded24hNotif
    Files_not_uploaded_48_ hrsNoneFiles uploaded successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotUploaded48hNotif
    Files_not_uploaded_48_ hrsHighAt least 1 file was not uploaded within 48 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotUploaded48hNotif
    Files_not_picked_up_24_ hrsNoneFiles picked up for processing successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotPicked24hNotif
    Files_not_picked_up_24_ hrsHighAt least 5 files were not picked up for processing within 24 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotPicked24hNotif
    Files_not_picked_up_48_ hrsNoneFiles picked up for processing successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotPicked48hNotif
    Files_not_picked_up_48_ hrsHighAt least 1 file was not picked up for processing within 48 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    filesNotPicked48hNotif
    Queryservice_statusNoneQueryservice is running.Run the command restart queryservice to restart the servicequeryServiceStatusNotif
    Queryservice_statusHighQueryservice is not running.Run the command restart queryservice to restart the servicequeryServiceStatusNotif
    Mongos_statusNoneMongos is running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    mongoSStatusNotif
    Mongos_statusHighMongos is not running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    mongoSStatusNotif
    Mongodb_statusNoneMongodb is running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    mongoDBStatusNotif
    Mongodb_statusHighMongodb is not running.Contact support and provide them the debug package.
    Run:
    troubleshooting debug-package generate
    mongoDBStatusNotif
    Threat_feed_ageNoneThe threat feed data on the device is up-to-date.threatfeedAgeNotif
    Auth_proxy_statusNoneAuth Proxy services have recovered.Contact support to resolve this issue.authProxyStatusNotif
    Auth_proxy_statusHighAuth Proxy services are down. Users may not be able to login to Microsoft Office 365.Contact support to resolve this issue.authProxyStatusNotif
    No_events_from_deviceNoneEvents from device were successfully sent.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    noEventsFromDeviceNotif
    No_events_from_deviceHighEvents from device not received in the last 24 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    noEventsFromDeviceNotif
    No_metrics_from_deviceNoneMetrics from device were successfully sent.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    noMetricsFromDeviceNotif
    No_metrics_from_deviceMediumMetrics from device were not received in the last 3 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    noMetricsFromDeviceNotif
    No_metrics_from_deviceHighMetrics from device were not received in the last 6 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    noMetricsFromDeviceNotif
    Storage-1aNoneDisk usage of /nslogs is below 50%.Check the available disk size of the /nslogs partition using the status all command.
    To increase the size of the partition contact support.
    Storage-1aMediumDisk usage of /nslogs is at 50% or more.Check the available disk size of the /nslogs partition using the status all command.
    To increase the size of the partition contact support.
    Storage-1aHighDisk usage of /nslogs is at 75% or more.Check the available disk size of the /nslogs partition using the status all command.
    To increase the size of the partition contact support.
    Log_Process-4NoneFiles were picked up.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-4MediumFiles were not being picked within 10 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-4HighFiles were not being picked within 15 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5aNoneFiles moved and split successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5aMediumFiles moved but not split within 24 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5aHighFiles moved but not split within 72 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5bNoneFiles moved & split and parsed successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5bMediumFiles moved & split, parsing not finished in 24 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5bHighFiles moved & split, parsing not finished in 72 hours.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5cNoneFile parsing finished; events uploaded successfully.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5cMediumFile parsing finished; events haven't been uploaded within 24 hours of parsing.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Log_Process-5cHighFile parsing finished; events haven't been uploaded within 72 hours of parsing done.Run the following command to see the list of unprocessed files:
    log-upload tools list
    If the list is zero, check your firewall to ensure that OPLP can access the tenant domains.
    For a complete list of supported tenant domains, see Outbound Ports.
    Contact support to resolve this issue.
    Callhome_statusNoneCallhome endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.callhomeConnectivityNotif
    Callhome_statusHighCallhome endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.callhomeConnectivityNotif
    Downloader_statusNoneDownloader endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.downloaderConnectivityNotif
    Downloader_statusHighDownloader endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.downloaderConnectivityNotif
    Config_service_statusNoneConfig service endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.configsvcConnectivityNotif
    Config_service_statusHighConfig service endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.configsvcConnectivityNotif
    UI_hostname_statusNoneHTTP endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.uihostnameConnectivityNotif
    UI_hostname_statusHighHTTP endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.uihostnameConnectivityNotif
    UI_hostname_ssh_statusNoneSSH endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.uihostnamesshConnectivityNotif
    UI_hostname_ssh_statusHighSSH endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.uihostnamesshConnectivityNotif
    Logupload_statusNoneLogupload endpoint is reachable.The domain always needs to be allowlisted and accessible to the appliance.loguploadConnectivityNotif
    Logupload_statusHighLogupload endpoint cannot be reached.The domain always needs to be allowlisted and accessible to the appliance.loguploadConnectivityNotif

    Outboard Ports

    Use these ports for management connectivity and log uploads.

    For management connectivity:

    Domain DescriptionPort
    config-<tenant-URL>Use for configuration updates. The domain needs to be SSL allowlisted if you have SSL decryption enabled. 443
    download-<tenant-URL>Use for software upgrades. 443
    messenger-<tenant-URL> Use for reporting and status updates in the UI. The domain needs to be SSL allowlisted if you have SSL decryption enabled.443
    callhome-<tenant-URL> Use for receiving metrics from on-premises appliances and forwarding them to cloud tenants, as well as receiving event data from an on-premises dataplane appliances. Also for receiving custom user attributes from user endpoints. The domain needs to be SSL allowlisted if you have SSL decryption enabled.443

    For log uploads:

    DomainDescription Port
    upload-<tenant-URL>Use for sending logs to the Netskope cloud with SFTP. This is the default port for log uploads. 22
    logupload-<tenant-URL>Use for sending logs to the Netskope cloud with HTTPS. This port is enabled by default. 443
    <tenant-URL> Use for fetching the REST API token with HTTPS. 443
    In this Topic
    • OPLP Alerts and Event Descriptions