Flow Trace for Logical Systems
Learn about flow trace and how to configure flow trace support for logical systems.
Flow trace also called traceoptions, monitors traffic flow into and out of a security device. You can use traceoptions as debugging tool to trace the packets as they traverse the security device. It also provides details of the device's actions.
Flow Trace Support for Logical Systems
A security device with logical systems configures traceoptions at the root level by default. All system traces, including root and tenant systems, are logged in one file, creating large amounts of information.
When you configure traceoptions at the logical system level, traces are logged in the respective tenant's trace file. You can create an output file and easily find traffic information in the trace file.
To enable traceoptions, specify the filename and the type of information you want to trace.
Flow traces are sent to one log file in root when you enable traceoptions under the root context. For tenant systems, enabling traceoptions sends traces to their respective trace files.
Configure Flow Trace Support for Logical Systems
Configuring traceoptions for a logical system includes configuring both a target file and a flag. The target file determines where the trace output is recorded. The flag defines what type of data is collected. If you configure traceoptions for a logical system, the respective trace file sent to the specific logical system log file only.
To configure traceoptions for a logical system:
After you commit the traceoptions configuration, you can view the traceoptions debug files for
the logical system using the command, show log
tracefilename.
user@host:LSYS1> show log flow_lsys1.log Nov 7 07:34:09 07:34:09.491800:CID-0:THREAD_ID-00:LSYS_ID-01:RT:got route table lock Nov 7 07:34:09 07:34:09.491809:CID-0:THREAD_ID-00:LSYS_ID-01:RT:released route table lock Nov 7 07:34:09 07:34:09.491840:CID-0:THREAD_ID-00:LSYS_ID-01:RT:got route table lock Nov 7 07:34:09 07:34:09.491841:CID-0:THREAD_ID-00:LSYS_ID-01:RT:released route table lock Nov 7 07:34:09 07:34:09.491854:CID-0:THREAD_ID-00:LSYS_ID-01:RT:cache final sw_nh 0x0 Nov 7 07:34:09 07:34:09.491868:CID-0:THREAD_ID-00:LSYS_ID-01:RT:got route table lock Nov 7 07:34:09 07:34:09.491869:CID-0:THREAD_ID-00:LSYS_ID-01:RT:released route table lock Nov 7 07:34:09 07:34:09.491881:CID-0:THREAD_ID-00:LSYS_ID-01:RT:cache final sw_nh 0x0
Change History Table
Feature support is determined by the platform and release you are using. Use Feature Explorer to determine if a feature is supported on your platform.