<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>identify spikes in traffic, ssl/tls and sessions before outage</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/140220/identify-spikes-in-traffic-ssl-tls-and-sessions-before-outage</link><description>Hey, 
 
 this noon our entire network crashed for a couple of minutes. 
 All i can see in our sophos portal is, that the &amp;quot;Sessions&amp;quot; graphs at the Control center --&amp;gt; &amp;quot;SSL/TLS&amp;quot; and &amp;quot;Network&amp;quot; spiked unusually high shortly before this outage happened. (see</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: identify spikes in traffic, ssl/tls and sessions before outage</title><link>https://community.sophos.com/thread/521245?ContentTypeID=1</link><pubDate>Wed, 19 Apr 2023 15:44:06 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6a3fafcd-5cf4-446e-8dc9-b4118ea1b308</guid><dc:creator>Erick Jan</dc:creator><description>&lt;p&gt;Hi Maximillian,&lt;/p&gt;
&lt;p&gt;Thank you for reaching out to Sophos Community.&lt;/p&gt;
&lt;p&gt;In the Log viewer, check the Firewall and IPS sections around the time of the incident if there was a spike. There may be additional hints about the problematic source.&lt;/p&gt;
&lt;p&gt;Also, you may want to check the following to troubleshoot the cause for future reference.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;1.Check system graph on WEB UI&lt;br /&gt;System graphs must cover the time of sudden reboot/crash, and &amp;quot;live graph&amp;quot; is preferred over &amp;quot;Today&amp;quot;, preferred over &amp;quot;Last 48 hours&amp;quot;&lt;/li&gt;
&lt;li&gt;2. Core Dump&lt;br /&gt;ls -lh /var/cores&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;login through Putty or console&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Advance Shell/CLI&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Click 5. Device Management then Click 3.Advance Shell/CLI&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;3. Check %CPU and Service with highest utilization by typing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; top&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; to exit click ctrl+c&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="/sophos-xg-firewall/f/recommended-reads/134787/sophos-firewall-understanding-top-and-atop-command-in-fw-utm"&gt;https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/134787/sophos-firewall-understanding-top-and-atop-command-in-xg-utm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You may also raise a ticket to Sophos Support for further assistance via the link&amp;nbsp;&lt;a href="https://soph.so/SophosSupport"&gt;https://soph.so/SophosSupport&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>