Device restarted (uptime low)-paloaltonetworks-panos

Device restarted (uptime low)-paloaltonetworks-panos
0

Device restarted (uptime low)-paloaltonetworks-panos

Vendor: paloaltonetworks

OS: panos

Description:
Indeni will alert when a device has restarted.

Remediation Steps:
Determine why the device was restarted.

How does this work?
This alert uses the Palo Alto Networks API to retrieve the current uptime (the equivalent of running “show system info” in the CLI).

Why is this important?
When a monitoring system loses connectivity to a device, it may be difficult for it to determine whether the device restarted, or is simply unreachable. To deal with that, the uptime is tracked. The uptime of a device resetting is a clear indicator of a device restart.

Without Indeni how would you find this?
An administrator will normally find out that a device has restarted when a service outage actually occurs.

panos-show-system-info-monitoring

Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/parsers/src/panw/panos/show-system-info-monitoring/show-system-info-monitoring.ind.yaml

cross_vendor_uptime_low

Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/rules/templatebased/crossvendor/cross_vendor_uptime_low.scala

Indeni Steps

  • get device current time

  • examine log for system reboot

  • check if any restart logs were found

  • show system files

  • check if system has crashed

  • system has crashed?

search for uptime low reason

Failed to fetch the data: https://bitbucket.org/indeni/indeni-knowledge/src/master/automation/playbooks/get_uptime_low_reason.yml