Device restarted (uptime low)-paloaltonetworks-panos
Indeni will alert when a device has restarted.
Determine why the device was restarted.
How does this work?
This alert uses the Palo Alto Networks API to retrieve the current uptime (the equivalent of running “show system info” in the CLI).
Why is this important?
When a monitoring system loses connectivity to a device, it may be difficult for it to determine whether the device restarted, or is simply unreachable. To deal with that, the uptime is tracked. The uptime of a device resetting is a clear indicator of a device restart.
Without Indeni how would you find this?
An administrator will normally find out that a device has restarted when a service outage actually occurs.
Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/parsers/src/panw/panos/show-system-info-monitoring/show-system-info-monitoring.ind.yaml
Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/rules/templatebased/crossvendor/cross_vendor_uptime_low.scala
get device current time
examine log for system reboot
check if any restart logs were found
show system files
check if system has crashed
system has crashed?
search for uptime low reason
Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/automation/playbooks/get_uptime_low_reason.yml