FortiNAC
FortiNAC is a s a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 190755

Description


This article describes the grab-log-snapshot report as one utility that collects a snapshot of a system's logfiles, stacktrace and memory information plus other information needed in order to diagnose a problem.  

 

This utility is very useful when problem descriptions similar to the following are reported to Support:

 

- The appliance is hung for some reason.

- See something about an OutOfMemory problem on the appliance.

- Perceived slow performance of the appliance/VM

- 'Processes are down' message on the GUI instead of the login.


Important: 

 

- The utility has to be run prior to a reboot of the appliance. In some instances, a reboot can destroy evidence of a problem.

- If Control Server/Application Server or High Availability pair, the script has to be run on each appliance.


Scope


Version: 8.x and greater.

 

Solution

 

GUI Instructions (available in versions 9.4, 7.2, and greater):
 
download logs 2.PNG

 

This will generate and download a snapshot of the logs directly from the browser. The status is shown at the bottom right of the screen.

 
See Download logs in the Administration Guide:

 

CLI Instructions for older versions:


1) Log into the CLI of the appliance as root.

2) Execute the script:


grab-log-snapshot


The script will collect and zip a large number of files.

This will take several minutes.

The resulting zip file (log-snapshot-<hostname>-<timestamp>.tar.gz) is located in /tmp directory.

Example.

grab-log-snapshot


This program grabs a snapshot of the system logfiles.
It takes several minutes to run.

Gathering logfiles...
Gathering system info....
Grabbing stacktraces....
Grabbing memory info....
Grabbing scheduler info....
Grabbing cluster network info....
Grabbing license info...
Packaging logfiles (takes a little while)...

All done.


Prelink messages that state that 'at least one of file's dependencies has changed since prelinking' can be ignored.

Logs are here: /tmp/log-snapshot-fortinac.forti.lab-20230428160858.tar.gz
Give this file to Support.

If a CPU performance or a memory-usage are experienced the problem, arrange with Support to run the collect-linux-debug-info script.

 

3) Retrieve the grab-log-snapshot file(s) to submit to Support.  This can be done using WinSCP or a similar application (specify SCP protocol) to download the files from the appliance.

4) Submit to Support. Open a support ticket and upload the files. Note: A comment must be added in order for the file to be saved.

 

If the file(s) are too big, contact Support for assistance.