Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Timothy_Hall
Legend Legend
Legend
Jump to solution

Extend fw ctl multik print_heavy_conn beyond 24 hours?

By default the command fw ctl multik print_heavy_conn will show all current and past elephant/heavy flows that were detected on the security gateway in the last 24 hours.  Questions:

1) Is there any way to tweak the 24 hours to some longer value?

2) Any way to keep some kind of historical log file of these elephant flows, even if it is just some kind of simple text file log on the gateway?

Thanks!

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
1 Solution

Accepted Solutions
AmitShmuel
Employee
Employee

Hi,

Starting R81 JHF T42 and R80.40 JHF T150, the CPU Spike Detective tool will run the print_heavy_conn command upon detecting a FW worker causing a CPU spike.

The output will be saved in /var/log/spike_detective/data_spike_thread_<Thread_ID>_<Date>_<Time>/heavy_conns_<Instance_ID>.log

It will also save the top connections by running the top_conns tool.

See sk166454.

Thanks,
Amit

View solution in original post

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

@Chen_Muchtar any idea?

0 Kudos
AmitShmuel
Employee
Employee

Hi,

Starting R81 JHF T42 and R80.40 JHF T150, the CPU Spike Detective tool will run the print_heavy_conn command upon detecting a FW worker causing a CPU spike.

The output will be saved in /var/log/spike_detective/data_spike_thread_<Thread_ID>_<Date>_<Time>/heavy_conns_<Instance_ID>.log

It will also save the top connections by running the top_conns tool.

See sk166454.

Thanks,
Amit

0 Kudos
Timothy_Hall
Legend Legend
Legend

Recently in my Gateway Performance Optimization class someone asked me why the spike detective doesn't log what connections were present at the time of spike, as it just logging that a worker USFW instance process got spiked was not particularly helpful.  Best answer I could give at the time was to check for spikes daily and run a print_heavy_conn within 24 hours of a logged spike.  This change will help a lot, thanks!

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events