: Diagnostic Tier Metrics
Focus
Focus
Table of Contents

Diagnostic Tier Metrics

Metrics in the diagnostic telemetry tier.
To ensure optimal security and peak performance of your Next-Generation Firewalls (NGFWs), Palo Alto Networks systematically gathers essential diagnostic information.
The following information is collected in 24-hours, 1-hour, and 5 minutes intervals.
  1. Device Information
    • Model and Serial Number
    • PAN-OS Software Version
    • Uptime and Last Reboot Time
    • Hardware Component Health (NPC cards, Power supply, Fan speed, system drive, transceivers)
    • High Availability (HA) State
    • Device Certificates (name and expiration date)
  2. System Resources and Health
    • CPU, Memory, Disk, and Buffer Utilization
    • Process/Daemon Health (for example, ssld, iked, and authd)
    • Interface/Tunnel Health (status, packet rate, drop rate)
    • Dataplane Throughput
    • NAT Pool (errors, utilization)
    • Logging Health (connectivity to external logging systems, log forwarding errors in PAN-OS, log buffer usage)
    • Commit Status (time, commit ID, success, failure)
    Configuration differences or full configuration information are not collected.
  3. Licenses and Enabled Features
    • License details: name, operational status, and expiration.
    • Enabled features (boolean: Yes/No):
      • SD-WAN
      • Decryption Policy/Profile
      • GlobalProtect
      • User-ID
      • Advanced CDSS Subscriptions
      • CASB/DLP
      • IoT
      • App-ID
      • Multi-vsys
Here are the relevant diagnostic tier metrics:
  • Decryption-Usage
  • Panorama Mode
  • User ID mapping-Type
  • CPU Load sampling per group
  • Hardware and Software Pools
  • Session table usage
  • System environmentals
  • percentage of Unknown-tcp and unknown-udp
  • Log generation rates for FWs
  • Core CPU utilization
  • SW buffer utilization
  • HW buffer utilization
  • Pool utilization count
  • POW performance output
  • Ingress backlogs
  • NAT pool utilization
  • HA1/backup, HA2/backup
  • Session Info
  • System disk-space
  • IP-User mapping
  • System Environmentals
  • Netstat
  • Session distribution statistics
  • System resources
  • System raid detail
  • System State
  • Firewalls (model) used
  • Power on hours
  • Temperature Measurements
  • Fan Speed measurements
  • Ports used
  • Power supply measurements
  • Front LED's status
  • systeminfo
  • User ID Agent state
  • Managed devices connection
  • High Availability State
  • show counter interface all
  • Device Logging Health
  • Panorama Logging Infra Health
  • Device Connection Status
  • Panorama HA Health
  • SDB for MP and DP CPU and Memory
  • Environmental Health Logs
  • Configuration Memory usage
  • Application Stats
  • POW Status output