<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148052/ips-log-filling-at-high-rate---normal-and-good-for-the-ssd-lifetime</link><description>Today we&amp;#39;ve had a partial outage due to high /var partition usage. 
 It was flapping between 70% and over 90% in a short time. 
 
 Firewall was rotating the IPS Logs at a high rate and compressing them caused additional CPU load. 
 The heartbeat service</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/549000?ContentTypeID=1</link><pubDate>Mon, 25 Nov 2024 08:27:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:40f689b7-9770-42ad-acbe-a11e9710b8f9</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;We will track this and also reduce the visibility of those debug commands, which are to &amp;quot;harsh&amp;quot; on the system to be only available if Sophos Support is involved.&amp;nbsp;&lt;br /&gt;Thanks for reporting!&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548999?ContentTypeID=1</link><pubDate>Mon, 25 Nov 2024 08:17:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:dc02a6c6-151a-4f63-a5f4-bc1328d52378</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;just for reference after the issue is fixed: &lt;/p&gt;
&lt;p&gt;this is how a regular ips.log would look like&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;2024-11-25T08:06:52.172001Z [25865/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:55909 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Stream [0xbe00683e;code:62;sub:104] Flow reset
2024-11-25T08:06:52.172116Z [25865/0x0] [nsg_tcphold.c:1568:tcp_hold_process_control] Failed to get tcp_hold_session ssnptr 0x1dcb7b10 (hold_state: 3).
2024-11-25T08:06:52.189184Z [25863/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:55951 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Stream [0xbe00683e;code:62;sub:104] Flow reset
2024-11-25T08:06:52.354643Z [25862/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:55911 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Stream [0xbe00683e;code:62;sub:104] Flow reset
2024-11-25T08:06:52.354802Z [25862/0x0] [nsg_tcphold.c:1568:tcp_hold_process_control] Failed to get tcp_hold_session ssnptr 0x1de148f0 (hold_state: 3).
2024-11-25T08:06:52.422138Z [25863/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57702 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
2024-11-25T08:06:52.654064Z [25865/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57704 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
2024-11-25T08:06:55.510853Z [25865/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57725 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
2024-11-25T08:06:55.558649Z [25865/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57723 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
2024-11-25T08:06:55.559531Z [25862/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57722 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
2024-11-25T08:06:55.618653Z [25862/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57721 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
2024-11-25T08:06:55.683107Z [25863/0x0] [nsg_nse_policy.c:1570:__nsg_error] xxx.xxx.xxx.xxx:57720 to xxx.xxx.xxx.xxx:443: Error from nse: NSE:Internal [0xb000058f;code:143;sub:5] Flow timeout
UST sessiontbl_get_tuple API returned -1
UST sessiontbl_get_tuple API returned -1
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;file growth is minimal:&lt;br /&gt;less than 10MB per minute&lt;br /&gt;92.&lt;strong&gt;5&lt;/strong&gt;M 09:14:37 /log/ips.log&lt;br /&gt;92.&lt;strong&gt;5&lt;/strong&gt;M 09:15:37 /log/ips.log&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548977?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 19:30:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:10cbb453-e890-466d-bb78-63726ca09e4e</guid><dc:creator>Michael Dunn</dc:creator><description>&lt;p&gt;This has occurred in a few cases recently where support/GES/partner/??? are not deleting debug flag files.&lt;br /&gt;&lt;br /&gt;awarrenhttp:&lt;br /&gt;/sdisk/tmp/debug.cfg&lt;br /&gt;&lt;br /&gt;ips:&lt;br /&gt;&lt;span&gt;/var/tmp/debugp.conf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Both awarrenhttp and ips have special debug flag files that allow for very finetuned levels of logging to be enabled and disabled (a mask of bits that turn on/off areas of logs) .&amp;nbsp; When awarrenhttp and ips are started they look for the presence of the file.&amp;nbsp; If found, they turn on DEBUG logging.&amp;nbsp; However there is no way of telling csc/service that DEBUG is on.&amp;nbsp; Therefore the output of the &amp;quot;service -S&amp;quot; command is incorrect.&lt;br /&gt;&lt;br /&gt;It is critical to do two things:&lt;br /&gt;1) Delete the flag files, ideally immediately after enabling debugging so you do not forget&lt;br /&gt;2) Do not rely on &amp;quot;service -S&amp;quot; to tell you if DEBUG is on.&amp;nbsp; Rely on the whether the log file&amp;nbsp;is filling up with debug lines.&lt;br /&gt;&lt;br /&gt;I did not know that we are publishing GES MER publicly.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548973?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 17:37:42 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f7b7ea18-bf77-4422-8d35-15460fea3093</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;Confirmed - Logs back to normal! Great and Thank you very much!&lt;/p&gt;
&lt;p&gt;And &lt;a href="/members/lucar-toni"&gt;LuCar Toni&lt;/a&gt; was on the right track from the beginning!&lt;/p&gt;
&lt;p&gt;I created /var/tmp/debugp.conf for the case mentioned here &amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/discussions/147925/webfilter-https-decryption-breaks-chatgpt-http-parsing-error-encountered"&gt;Webfilter HTTPS decryption breaks ChatGPT: HTTP parsing error encountered&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;That file contained my own IP address for the ChatGPT debug.&lt;/p&gt;
&lt;p&gt;LuCar mentionend &amp;nbsp;&lt;a href="/sophos-xg-firewall/f/discussions/145539/ips-log-filling-up-disk"&gt;https://community.sophos.com/sophos-xg-firewall/f/discussions/145539/ips-log-filling-up-disk&lt;/a&gt; where &lt;a href="/members/michael-dunn"&gt;Michael Dunn&lt;/a&gt;&amp;nbsp;suggested to search and delete the debugp log file. I missed that.&lt;/p&gt;
&lt;p&gt;Debug was enabled/disabled 3 times using &lt;span&gt;&lt;strong&gt;service -ds nosync ips:debugp &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&amp;nbsp;&lt;a href="/members/nileshpatel"&gt;NileshPatel&lt;/a&gt; I communicated 4 times, but found only 6 status code 200 response.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;service -ds nosync ips:debugp
200 OK&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;I expected the file to be ignored when &lt;span&gt;&lt;strong&gt;service -ds nosync ips:debugp&lt;/strong&gt;&lt;/span&gt; was used to disable debug again.&lt;/p&gt;
&lt;p&gt;Eventually it enables itself again when the firewall is rebooted? That could be checked. Nilesh wrote me, when IPS starts, it loads the &lt;span&gt;&lt;strong&gt;debugp&lt;/strong&gt;&lt;/span&gt; file. That was the case here because the firewall was rebooted one&amp;nbsp; week ago for the v21 upgrade.&lt;/p&gt;
&lt;p&gt;Sooner or later this wold have happened anyway.&lt;/p&gt;
&lt;p&gt;So it&amp;#39;s very important to delete the &lt;span&gt;&lt;strong&gt;debugp&lt;/strong&gt;&lt;/span&gt; file after the tests or at least have it containing only&lt;/p&gt;
&lt;p&gt;mask=0&lt;/p&gt;
&lt;p&gt;Maybe that is something for the Doc Team @R&lt;a href="/members/r_4000_docsupport"&gt;R@DocSupport&lt;/a&gt;&amp;nbsp; for the article &lt;a href="https://support.sophos.com/support/s/article/KBA-000006577?language=en_US"&gt;https://support.sophos.com/support/s/article/KBA-000006577?language=en_US&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Thanks a lot everyone involved here! It was an exciting experience!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548972?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 17:22:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:15fa7cdf-7b86-4cc1-a429-a23aa3951109</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;checking SSH session logs I remembered I enabled a debug my self. more below to keep it readable here.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548971?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 17:21:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9d378e19-0d6b-49ea-967a-4737ffdb124f</guid><dc:creator>NileshPatel</dc:creator><description>&lt;div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;div dir="auto" data-message-author-role="assistant" data-message-id="746dc710-607a-4898-8586-b3150f7fe7a7" data-client-thread-id="WEB:5dd4a60c-5472-4708-9092-4b3ebda680b4" data-message-model-slug="gpt-4o-mini"&gt;
&lt;div&gt;
&lt;div&gt;
&lt;p&gt;The debugp mask was configured in &lt;code&gt;/var/tmp/debugp.conf&lt;/code&gt;, which enabled debugging. To disable it, you might have run the command &lt;code&gt;service ips:debugp -ds nosync&lt;/code&gt;. However, existing connections will still use the mask that was set when they first arrived.&lt;/p&gt;
&lt;p&gt;I have updated the mask to &lt;code&gt;0&lt;/code&gt; in &lt;code&gt;/var/tmp/debugp.conf&lt;/code&gt; and restarted the IPS, which has fully disabled the WIS debug mode. The IPS restart also resolved the CSC status issue.&lt;/p&gt;
&lt;p&gt;No debug logs are being generated after the IPS restart. Please confirm.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548970?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 16:09:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a259f8d6-d9c4-4d0d-8ee2-95bd07a4e6fd</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;case 02001662 / Webfilter HTTPS decryption breaks ChatGPT: HTTP parsing error encountered&lt;/p&gt;
&lt;p&gt;was about IPS but I got no notification debug or hidden debug was enabled.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548969?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 15:58:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:25e4812a-8884-4a72-8e03-82de819aa736</guid><dc:creator>NileshPatel</dc:creator><description>&lt;p&gt;&lt;span&gt;service -S |grep -i ips is showing opposite status hence you are seeing less logs when you enable debug (which actually disabled the debug). we are looking into this issue.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548968?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 15:31:12 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b2c5245b-6cd7-434f-8538-9d5a81cdb623</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;we observed that IPS in Debug mode logs way less than when running in non-Debug mode.&lt;/p&gt;
&lt;p&gt;Factor was about 1:4&lt;/p&gt;
&lt;p&gt;In non-debug there was all the connection information in the logs.&lt;/p&gt;
&lt;p&gt;GES believes there is some kind of low-level default Debug enabled, which is ruled out when the service is put to debug mode.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;NON-DEBUG:
2024-11-22T15:03:20.480455Z [27128] daq_metadata session id 5694 rev 6056 appid 0  hbappid 0 idp 18 appfltid 0
2024-11-22T15:03:20.480461Z [27128] verdict 0 pktnum 21011930 flowoff [IPS|WEB|AV] appcat [0:0] dsize 388 [xxx.xxx.xxx.xxx:46620 -&amp;gt; xxx.xxx.xxx.xxx:514]
2024-11-22T15:03:20.480464Z [27128] daq_metadata session id 5694 rev 6056 appid 0  hbappid 0 idp 18 appfltid 0
2024-11-22T15:03:20.480468Z [27128] verdict 0 pktnum 21011931 flowoff [IPS|WEB|AV] appcat [0:0] dsize 401 [xxx.xxx.xxx.xxx:46620 -&amp;gt; xxx.xxx.xxx.xxx:514]
2024-11-22T15:03:20.480470Z [27128] daq_metadata session id 5694 rev 6056 appid 0  hbappid 0 idp 18 appfltid 0
2024-11-22T15:03:20.480475Z [27128] verdict 0 pktnum 21011932 flowoff [IPS|WEB|AV] appcat [0:0] dsize 400 [xxx.xxx.xxx.xxx:46620 -&amp;gt; xxx.xxx.xxx.xxx:514]
2024-11-22T15:03:20.480477Z [27128] daq_metadata session id 5694 rev 6056 appid 0  hbappid 0 idp 18 appfltid 0
2024-11-22T15:03:20.480482Z [27128] verdict 0 pktnum 21011933 flowoff [IPS|WEB|AV] appcat [0:0] dsize 389 [xxx.xxx.xxx.xxx:46620 -&amp;gt; xxx.xxx.xxx.xxx:514]
2024-11-22T15:03:20.480523Z [27128] daq_metadata session id 12985 rev 11175 appid 2712  hbappid 0 idp 5 appfltid 4
2024-11-22T15:03:20.480533Z [27128] verdict 0 pktnum 7752 flowoff [APP|WEB|AV] appcat [2712:5] dsize 25 [xxx.xxx.xxx.xxx:443 -&amp;gt; xxx.xxx.xxx.xxx:42054]
2024-11-22T15:03:20.480604Z [27128] daq_metadata session id 12985 rev 11175 appid 2712  hbappid 0 idp 5 appfltid 4
2024-11-22T15:03:20.480612Z [27128] verdict 0 pktnum 7753 flowoff [APP|WEB|AV] appcat [2712:5] dsize 1250 [xxx.xxx.xxx.xxx:443 -&amp;gt; xxx.xxx.xxx.xxx:42054]
2024-11-22T15:03:20.480650Z [27128] daq_metadata session id 12985 rev 11175 appid 2712  hbappid 0 idp 5 appfltid 4
2024-11-22T15:03:20.480656Z [27128] verdict 0 pktnum 7754 flowoff [APP|WEB|AV] appcat [2712:5] dsize 1250 [xxx.xxx.xxx.xxx:443 -&amp;gt; xxx.xxx.xxx.xxx:42054]


DEBUG:
2024-11-22T15:00:19.086120Z [27127/0x57ea000049e5] [nsg_request_fsm.c:542:request_fsm_body_bytes] Event body_bytes in state RESP_PARSE_BODY_SKIP
2024-11-22T15:00:19.086192Z [27127/0x57ea000049e5] [acl/acl_lookup.c:608:check_access_list] ACL check: USER matched for WEB rule 0 (user-id=24)
2024-11-22T15:00:19.086196Z [27127/0x57ea000049e5] [acl/acl_lookup.c:611:check_access_list] checking policy [000], if matched, allow
2024-11-22T15:00:19.086199Z [27127/0x57ea000049e5] [acl/acl_lookup.c:392:__check_acl] checking &amp;#39;all type 1&amp;#39;
2024-11-22T15:00:19.086202Z [27127/0x57ea000049e5] [acl/acl_lookup.c:623:check_access_list] All ACLs matched: rule action = allow
2024-11-22T15:00:19.086206Z [27127/0x57ea000049e5] [nsg_request_fsm.c:542:request_fsm_body_bytes] Event body_bytes in state RESP_PARSE_BODY_SKIP
2024-11-22T15:00:19.086209Z [27127/0x57ea000049e5] [acl/acl_lookup.c:608:check_access_list] ACL check: USER matched for WEB rule 0 (user-id=24)
2024-11-22T15:00:19.086211Z [27127/0x57ea000049e5] [acl/acl_lookup.c:611:check_access_list] checking policy [000], if matched, allow
2024-11-22T15:00:19.086213Z [27127/0x57ea000049e5] [acl/acl_lookup.c:392:__check_acl] checking &amp;#39;all type 1&amp;#39;
2024-11-22T15:00:19.086216Z [27127/0x57ea000049e5] [acl/acl_lookup.c:623:check_access_list] All ACLs matched: rule action = allow
2024-11-22T15:00:19.086218Z [27127/0x57ea000049e5] [nsg_request_fsm.c:542:request_fsm_body_bytes] Event body_bytes in state RESP_PARSE_BODY_SKIP
2024-11-22T15:00:19.086230Z [27127/0x57ea000049e5] [acl/acl_lookup.c:608:check_access_list] ACL check: USER matched for WEB rule 0 (user-id=24)
2024-11-22T15:00:19.086232Z [27127/0x57ea000049e5] [acl/acl_lookup.c:611:check_access_list] checking policy [000], if matched, allow
&lt;/pre&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548952?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 14:13:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:319cca40-9551-4849-a11b-2913067dfb48</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;no, sorry, the service is not running in debug triple confirmed by Sophos Support and me.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;meanwhile even the zipped .gz files getting bigger and bigger now reaching about 2GB while they were at 300MB yesterday&lt;/p&gt;
&lt;p&gt;/dev/var&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 179.3G&amp;nbsp;&amp;nbsp;&amp;nbsp; 112.3G&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67.0G&amp;nbsp; 63% /var&lt;br /&gt;ls -lhS --full-time /log/ips.* | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;&lt;strong&gt;41.2G&lt;/strong&gt; 14:48:56 /log/ips.log-20241122_143858&lt;br /&gt;&lt;strong&gt;28.5G&lt;/strong&gt; 15:09:24 /log/ips.log&lt;br /&gt;2.3G 12:36:43 /log/ips.log-20241122_123643.gz&lt;br /&gt;1.9G 13:06:46 /log/ips.log-20241122_130646.gz&lt;br /&gt;1.8G 15:09:24 /log/ips.log-20241122_143858.gz&lt;br /&gt;1.7G 14:13:53 /log/ips.log-20241122_141353.gz&lt;br /&gt;1.7G 13:30:50 /log/ips.log-20241122_133050.gz&lt;br /&gt;1.5G 13:52:49 /log/ips.log-20241122_135249.gz&lt;br /&gt;XGS4500_AM02_SFOS 21.0.0 GA-Build169 HA-Primary# service -S |grep -i ips&lt;br /&gt;ips&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RUNNING&lt;br /&gt;ipsec-monitor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RUNNING&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Debug would show&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;service -S |grep -i ips&lt;br /&gt;ips&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RUNNING,DEBUG&lt;br /&gt;ipsec-monitor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RUNNING&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;GES is working on the issue. Confirmed logging is not normal.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548950?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 14:02:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9eeb5faf-4eb8-4ea2-ab1f-39d3f96cb596</guid><dc:creator>NileshPatel</dc:creator><description>&lt;p&gt;IPS debugging is currently enabled. You can toggle the debugging by using the command below.&lt;/p&gt;
&lt;p&gt;service ips:debug -ds nosync&lt;/p&gt;
&lt;p&gt;This won&amp;#39;t be enabled by default. Was it enabled manually?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548940?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 09:34:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f4d42b3a-3587-4889-80f7-1c6067fb8111</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;and now I observe, it does not log-rotate correctly at the moment. files growing bigger and bigger.&lt;br /&gt;That must be the same situation as yesterday.&lt;/p&gt;
&lt;p&gt;ls -lhS --full-time /log/ips.* | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;&lt;strong&gt;25.7G&lt;/strong&gt; 10:32:36 /log/ips.log&lt;br /&gt;&lt;strong&gt;17.3G &lt;/strong&gt;10:32:36 /log/ips.log-20241122_102838&lt;br /&gt;745.0M 10:16:12 /log/ips.log-20241122_101612.gz&lt;br /&gt;557.8M 09:52:04 /log/ips.log-20241122_095204.gz&lt;br /&gt;479.4M 09:58:58 /log/ips.log-20241122_095858.gz&lt;br /&gt;461.3M 10:04:36 /log/ips.log-20241122_100436.gz&lt;br /&gt;436.6M 10:10:14 /log/ips.log-20241122_101014.gz&lt;/p&gt;
&lt;p&gt;an absolutely dangerous situation:&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " height="276" src="/resized-image/__size/1470x552/__key/communityserver-discussions-components-files/126/pastedimage1732268424259v1.png" width="735" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1732280185350v4.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548939?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 09:19:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d518dcc4-b984-485c-9452-46a08e07d681</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;there is not much of an example in that thread but I think they&amp;#39;ve had an issue with log lines repeating &amp;quot;jumbogram&amp;quot; string.&lt;/p&gt;
&lt;p&gt;Also they were talking about some MB per minute, not GB like here on my XGS:&lt;/p&gt;
&lt;p&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;9.2G 10:17:13 /log/ips.log&lt;br /&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;9.3G 10:17:17 /log/ips.log&lt;br /&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;9.4G 10:17:21 /log/ips.log&lt;br /&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;9.6G 10:17:25 /log/ips.log&lt;br /&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7,$9}&amp;#39;&lt;br /&gt;9.8G 10:17:29 /log/ips.log&lt;/p&gt;
&lt;p&gt;-&lt;/p&gt;
&lt;p&gt;-ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7}&amp;#39;&lt;br /&gt;2.4G 10:20:20&lt;br /&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7}&amp;#39;&lt;br /&gt;7.0G 10:22:59&lt;br /&gt;ls -lhS --full-time /log/ips.log | awk &amp;#39;{print $5,$7}&amp;#39;&lt;br /&gt;14.2G 10:26:31&lt;/p&gt;
&lt;p&gt;Our log file looks like above - it looks like this even when the IPS scanning is disabled but the IPS service is running. The screenshot from yesterday:&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " height="114" src="/resized-image/__size/764x228/__key/communityserver-discussions-components-files/126/pastedimage1732266147822v1.png" width="382" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;ips.log contains logs about every connection and some other event, too.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548935?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 08:46:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:99ce2954-4abf-4b0b-a84f-3b1924b1341c</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;The logs do not look like this?&amp;nbsp;&amp;nbsp;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/discussions/145539/ips-log-filling-up-disk/539023"&gt;RE: ips.log filling up disk&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548933?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 08:34:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9bba0847-4bd6-412c-86aa-9ed85ec54059</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;@Sophos do we have a confirmation that ips.log should be as noisy as it is? How would a ips.log look like on a random mid size firewall?&lt;/p&gt;
&lt;p&gt;Those tiny CPU peaks every ode or two minute are only because the firewall is compressing new IPS logs into the .gz files all the time.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1732264218457v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;lines from our ips.log. look at the timestamps.&lt;br /&gt;&lt;pre class="ui-code" data-mode="text"&gt;2024-11-22T08:32:13.206874Z [27132] verdict 0 pktnum 246732 flowoff [APP|AV] appcat [22245:25] dsize 1460 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:49524]
2024-11-22T08:32:13.206877Z [27132] daq_metadata session id 10238 rev 9840 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.206883Z [27132] verdict 0 pktnum 246733 flowoff [APP|AV] appcat [22245:25] dsize 1460 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:49524]
2024-11-22T08:32:13.206885Z [27132] daq_metadata session id 10238 rev 9840 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.206891Z [27132] verdict 0 pktnum 246734 flowoff [APP|AV] appcat [22245:25] dsize 362 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:49524]
2024-11-22T08:32:13.207020Z [27128] daq_metadata session id 16708 rev 44417 appid 100  hbappid 0 idp 6 appfltid 3
2024-11-22T08:32:13.207031Z [27128] verdict 3 pktnum 40 flowoff [APP|WEB|AV] appcat [100:5] dsize 0 [xxx.xxx.xxx.xxx:57041 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207187Z [27132] daq_metadata session id 186 rev 30620 appid 0  hbappid 0 idp 18 appfltid 0
2024-11-22T08:32:13.207194Z [27132] verdict 0 pktnum 1904446 flowoff [IPS|WEB|AV] appcat [0:0] dsize 186 [xxx.xxx.xxx.xxx:43153 -&amp;gt; xxx.xxx.xxx.xxx:514]
2024-11-22T08:32:13.207387Z [27128] daq_metadata session id 19369 rev 24179 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207403Z [27128] verdict 0 pktnum 42303 flowoff [APP|AV] appcat [22245:25] dsize 76 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:62628]
2024-11-22T08:32:13.207418Z [27132] daq_metadata session id 11766 rev 21901 appid 100  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207426Z [27132] verdict 3 pktnum 677 flowoff [APP|WEB|AV] appcat [100:5] dsize 0 [xxx.xxx.xxx.xxx:40222 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207460Z [27128] daq_metadata session id 13230 rev 4211 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207490Z [27128] verdict 0 pktnum 590486 flowoff [APP|AV] appcat [22245:25] dsize 92 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:57352]
2024-11-22T08:32:13.207505Z [27128] daq_metadata session id 1827 rev 52159 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207522Z [27132] daq_metadata session id 15394 rev 58396 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207522Z [27127] daq_metadata session id 19396 rev 48441 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207527Z [27128] verdict 0 pktnum 48110 flowoff [APP|AV] appcat [22245:25] dsize 140 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:62620]
2024-11-22T08:32:13.207538Z [27127] verdict 0 pktnum 48051 flowoff [APP|AV] appcat [22245:25] dsize 140 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:61487]
2024-11-22T08:32:13.207543Z [27132] verdict 0 pktnum 48182 flowoff [APP|AV] appcat [22245:25] dsize 140 [xxx.xxx.xxx.xxx:55752 -&amp;gt; xxx.xxx.xxx.xxx:49507]
2024-11-22T08:32:13.207589Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207600Z [27127] verdict 0 pktnum 49464 flowoff [APP|WEB|AV] appcat [20019:25] dsize 1460 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207603Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207612Z [27127] verdict 0 pktnum 49465 flowoff [APP|WEB|AV] appcat [20019:25] dsize 1460 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207614Z [27132] daq_metadata session id 11766 rev 21901 appid 100  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207615Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207625Z [27127] verdict 0 pktnum 49466 flowoff [APP|WEB|AV] appcat [20019:25] dsize 1460 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207629Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207633Z [27132] verdict 3 pktnum 678 flowoff [APP|WEB|AV] appcat [100:5] dsize 0 [xxx.xxx.xxx.xxx:40222 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207639Z [27127] verdict 0 pktnum 49467 flowoff [APP|WEB|AV] appcat [20019:25] dsize 1460 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207642Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207646Z [27132] daq_metadata session id 7348 rev 8853 appid 2792  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207647Z [27128] daq_metadata session id 1875 rev 27197 appid 0  hbappid 0 idp 6 appfltid 0
2024-11-22T08:32:13.207653Z [27127] verdict 0 pktnum 49468 flowoff [APP|WEB|AV] appcat [20019:25] dsize 1460 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207656Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207655Z [27132] verdict 3 pktnum 94 flowoff [APP|WEB|AV] appcat [2792:12] dsize 0 [xxx.xxx.xxx.xxx:33666 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207660Z [27132] daq_metadata session id 11766 rev 21901 appid 100  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207665Z [27127] verdict 0 pktnum 49469 flowoff [APP|WEB|AV] appcat [20019:25] dsize 1460 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207658Z [27128] verdict 0 pktnum 62572 flowoff [IPS|APP] appcat [0:0] dsize 168 [xxx.xxx.xxx.xxx:42078 -&amp;gt; xxx.xxx.xxx.xxx:9997]
2024-11-22T08:32:13.207668Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207669Z [27132] verdict 3 pktnum 679 flowoff [APP|WEB|AV] appcat [100:5] dsize 0 [xxx.xxx.xxx.xxx:40222 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207677Z [27127] verdict 0 pktnum 49470 flowoff [APP|WEB|AV] appcat [20019:25] dsize 729 [xxx.xxx.xxx.xxx:60979 -&amp;gt; xxx.xxx.xxx.xxx:3268]
2024-11-22T08:32:13.207682Z [27132] daq_metadata session id 11766 rev 21901 appid 100  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207689Z [27132] verdict 3 pktnum 680 flowoff [APP|WEB|AV] appcat [100:5] dsize 0 [xxx.xxx.xxx.xxx:40222 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207788Z [27128] daq_metadata session id 1875 rev 27197 appid 0  hbappid 0 idp 6 appfltid 0
2024-11-22T08:32:13.207793Z [27127] daq_metadata session id 19396 rev 48441 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207798Z [27128] verdict 0 pktnum 62519 flowoff [IPS|APP] appcat [0:0] dsize 0 [xxx.xxx.xxx.xxx:9997 -&amp;gt; xxx.xxx.xxx.xxx:42078]
2024-11-22T08:32:13.207805Z [27127] verdict 0 pktnum 35805 flowoff [APP|AV] appcat [22245:25] dsize 0 [xxx.xxx.xxx.xxx:61487 -&amp;gt; xxx.xxx.xxx.xxx:55752]
2024-11-22T08:32:13.207816Z [27132] daq_metadata session id 11766 rev 21901 appid 100  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207824Z [27132] verdict 3 pktnum 681 flowoff [APP|WEB|AV] appcat [100:5] dsize 0 [xxx.xxx.xxx.xxx:40222 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207843Z [27128] daq_metadata session id 13230 rev 4211 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207853Z [27128] verdict 0 pktnum 545486 flowoff [APP|AV] appcat [22245:25] dsize 0 [xxx.xxx.xxx.xxx:57352 -&amp;gt; xxx.xxx.xxx.xxx:55752]
2024-11-22T08:32:13.207865Z [27128] daq_metadata session id 1827 rev 52159 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207874Z [27128] verdict 0 pktnum 33047 flowoff [APP|AV] appcat [22245:25] dsize 0 [xxx.xxx.xxx.xxx:62620 -&amp;gt; xxx.xxx.xxx.xxx:55752]
2024-11-22T08:32:13.207877Z [27128] daq_metadata session id 19369 rev 24179 appid 22245  hbappid 22245 idp 6 appfltid 3
2024-11-22T08:32:13.207878Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207885Z [27128] verdict 0 pktnum 22436 flowoff [APP|AV] appcat [22245:25] dsize 0 [xxx.xxx.xxx.xxx:62628 -&amp;gt; xxx.xxx.xxx.xxx:55752]
2024-11-22T08:32:13.207887Z [27127] verdict 0 pktnum 32526 flowoff [APP|WEB|AV] appcat [20019:25] dsize 0 [xxx.xxx.xxx.xxx:3268 -&amp;gt; xxx.xxx.xxx.xxx:60979]
2024-11-22T08:32:13.207908Z [27127] daq_metadata session id 17528 rev 26228 appid 20019  hbappid 20019 idp 14 appfltid 0
2024-11-22T08:32:13.207915Z [27127] verdict 0 pktnum 32527 flowoff [APP|WEB|AV] appcat [20019:25] dsize 0 [xxx.xxx.xxx.xxx:3268 -&amp;gt; xxx.xxx.xxx.xxx:60979]
2024-11-22T08:32:13.207926Z [27127] daq_metadata session id 6610 rev 8910 appid 19433  hbappid 19433 idp 6 appfltid 0
2024-11-22T08:32:13.207936Z [27127] verdict 0 pktnum 93598 flowoff [APP|WEB|AV] appcat [19433:25] dsize 10 [xxx.xxx.xxx.xxx:49761 -&amp;gt; xxx.xxx.xxx.xxx:3389]
2024-11-22T08:32:13.207942Z [27132] daq_metadata session id 7348 rev 8853 appid 2792  hbappid 0 idp 5 appfltid 4
2024-11-22T08:32:13.207950Z [27132] verdict 3 pktnum 95 flowoff [APP|WEB|AV] appcat [2792:12] dsize 0 [xxx.xxx.xxx.xxx:33666 -&amp;gt; xxx.xxx.xxx.xxx:443]
2024-11-22T08:32:13.207991Z [27128] daq_metadata session id 1875 rev 27197 appid 0  hbappid 0 idp 6 appfltid 0
2024-11-22T08:32:13.207999Z [27128] verdict 0 pktnum 62573 flowoff [IPS|APP] appcat [0:0] dsize 43 [xxx.xxx.xxx.xxx:42078 -&amp;gt; xxx.xxx.xxx.xxx:9997]
2024-11-22T08:32:13.208085Z [27128] daq_metadata session id 1875 rev 27197 appid 0  hbappid 0 idp 6 appfltid 0
2024-11-22T08:32:13.208092Z [27128] verdict 0 pktnum 62520 flowoff [IPS|APP] appcat [0:0] dsize 0 [xxx.xxx.xxx.xxx:9997 -&amp;gt; xxx.xxx.xxx.xxx:42078]
&lt;/pre&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling at high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548910?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 14:56:31 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:297ff5a4-a623-468c-9de4-37f735fad481</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;the 24GB ips stale log file has been archived and then deleted manually.&lt;br /&gt;and two other screenshots&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1732200903350v1.png" alt=" " /&gt; &lt;img src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1732200979145v4.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548906?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 13:21:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:00b2d07b-dbca-4776-a6c8-fcaf11f85464</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;for the IPS Drops we&amp;#39;re seeing massively today it seems to be related to this URL&lt;/p&gt;
&lt;p&gt;2024-11-21 10:07:26Web filtermessageid=&amp;quot;16001&amp;quot; log_type=&amp;quot;Content Filtering&amp;quot; log_component=&amp;quot;HTTP&amp;quot; log_subtype=&amp;quot;Allowed&amp;quot; fw_rule_id=&amp;quot;2&amp;quot; fw_rule_name=&amp;quot;User-2-WAN&amp;quot; fw_rule_section=&amp;quot;Local rule&amp;quot; user=&amp;quot;user@domain&amp;quot; user_group=&amp;quot;OU=OU,DC=domain&amp;quot; web_policy_id=&amp;quot;4&amp;quot; web_policy=&amp;quot;OUR_DefaultPolicy&amp;quot; category=&amp;quot;Advertisements&amp;quot; category_type=&amp;quot;Unproductive&amp;quot; url=&amp;quot;https:/&lt;strong&gt;/ih.adscale.de&lt;/strong&gt;/adscale-ih/tpui?tpid=48&amp;amp;tpuid=-###truncated###-ayA4IB&amp;quot; content_type=&amp;quot;&amp;quot; override_token=&amp;quot;&amp;quot; src_ip=&amp;quot;172.xxx.xxx.82&amp;quot; dst_ip=&amp;quot;3.120.35.187&amp;quot; protocol=&amp;quot;TCP&amp;quot; src_port=&amp;quot;60035&amp;quot; dst_port=&amp;quot;443&amp;quot; bytes_sent=&amp;quot;1489&amp;quot; bytes_received=&amp;quot;2603&amp;quot; domain=&amp;quot;ih.adscale.de&amp;quot; exception=&amp;quot;&amp;quot; activity_name=&amp;quot;&amp;quot; reason=&amp;quot;&amp;quot; user_agent=&amp;quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0&amp;quot; status_code=&amp;quot;302&amp;quot; transaction_id=&amp;quot;feeedb56-f36f-46cf-a9f7-be58abb1c5e0&amp;quot; referer=&amp;quot;&amp;quot; download_file_name=&amp;quot;&amp;quot; download_file_type=&amp;quot;&amp;quot; upload_file_name=&amp;quot;&amp;quot; upload_file_type=&amp;quot;&amp;quot; con_id=&amp;quot;500959744&amp;quot; app_name=&amp;quot;&amp;quot; app_is_cloud=&amp;quot;0&amp;quot; override_name=&amp;quot;&amp;quot; override_authorizer=&amp;quot;&amp;quot; used_quota=&amp;quot;0&amp;quot;&lt;/p&gt;
&lt;p&gt;2024-11-21 10:07:26IPSmessageid=&amp;quot;07002&amp;quot; log_type=&amp;quot;IDP&amp;quot; log_component=&amp;quot;Signatures&amp;quot; log_subtype=&amp;quot;Drop&amp;quot; ips_policy=&amp;quot;&amp;quot; ips_policy_id=&amp;quot;16&amp;quot; fw_rule_id=&amp;quot;2&amp;quot; fw_rule_name=&amp;quot;User-2-WAN&amp;quot; fw_rule_section=&amp;quot;Local rule&amp;quot; user=&amp;quot;user@domain&amp;quot; sig_id=&amp;quot;20583&amp;quot; message=&amp;quot;BROWSER-FIREFOX Mozilla multiple location headers malicious redirect attempt&amp;quot; classification=&amp;quot;Web Application Attack&amp;quot; rule_priority=&amp;quot;3&amp;quot; src_ip=&amp;quot;3.120.35.187&amp;quot; src_country=&amp;quot;DEU&amp;quot; dst_ip=&amp;quot;172.xxx.xxx.82&amp;quot; dst_country=&amp;quot;R1&amp;quot; protocol=&amp;quot;TCP&amp;quot; src_port=&amp;quot;443&amp;quot; dst_port=&amp;quot;60035&amp;quot; OS=&amp;quot;Windows&amp;quot; category=&amp;quot;browser-firefox&amp;quot; victim=&amp;quot;Client&amp;quot;&lt;/p&gt;
&lt;p&gt;also for other IPs&lt;/p&gt;
&lt;p&gt;&lt;img alt=" " src="/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/126/pastedimage1732195343828v1.png" /&gt;&lt;/p&gt;
&lt;p&gt;we&amp;#39;ll block this FQDN&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548904?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 13:14:58 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:09392dfc-1b73-4b6f-925f-2ba51a96e64b</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;sure&lt;/p&gt;
&lt;p&gt;no results.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;cat /log/applog.log* | grep -i &amp;quot;log_rotate:exec Failed&amp;quot;&lt;/p&gt;
&lt;p&gt;ls applog.log* -l&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 28427822 Nov 21 14:12 applog.log&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2933453 Nov 14 09:14 applog.log-20241114_091429.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3938860 Nov 14 15:15 applog.log-20241114_151521.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2939131 Nov 15 06:48 applog.log-20241115_064840.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3690161 Nov 15 14:11 applog.log-20241115_141123.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3148974 Nov 16 04:24 applog.log-20241116_042414.gz&lt;/p&gt;
&lt;p&gt;zcat /log/applog.*.gz | grep -i &amp;quot;log_rotate:exec Failed&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;cat /log/applog.log | grep -i &amp;quot;failed&amp;quot;&lt;/p&gt;
&lt;p&gt;...&lt;br /&gt;Nov 21 04:10:00Z SendAppFeedback: app-feedback command failed. Details can be found in /log/app-feedback.log&lt;br /&gt;Nov 21 06:30:20Z getModuleInformation opcode failed&lt;br /&gt;Nov 21 06:30:20Z getModuleInformation opcode failed&lt;br /&gt;Nov 21 09:04:20Z Get random adminpassword state failed&lt;br /&gt;Nov 21 09:19:06Z Get random adminpassword state failed&lt;br /&gt;next logs are after the reboot.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548903?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 13:14:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:655db740-7635-4217-b0d5-ab25b938b717</guid><dc:creator>Raphael Alganes</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Regret to hear about your issue. Thank you for sharing support case, we shall be tracking progress on our end.&lt;/p&gt;
&lt;p&gt;Thank you for your patience&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548901?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 13:09:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6a547f17-7d7e-43dd-b45d-3933608e19fc</guid><dc:creator>Mayur Makvana</dc:creator><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Can you share the output of below?&lt;/p&gt;
&lt;p&gt;cat /log/applog.log | grep -i &amp;quot;log_rotate:exec Failed&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548900?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 13:04:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5fac443b-9ded-4477-85dd-9469ba9e02ca</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;for heartbeat, yes, but not for IPS&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548899?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 13:01:31 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c548bf23-5b51-4251-b168-e8605d121165</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Did you create for this XGS Appliance an case before? Because it looks like, there was special debugging enabled.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548898?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 12:56:59 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:559a3f13-c61e-4bb3-abb7-04d1b0aad5e2</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;no, IPS was not in debug. &lt;/p&gt;
&lt;p&gt;When we enabled IPS debug today the fill rate was not much changed to without debug.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548897?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 12:54:14 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0ee8b946-a6ae-4743-b5b6-2f85ab62178c</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Maybe someone in a older support ID enabled IPS Debugging?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: ips.log filling hat high rate - normal and good for the SSD lifetime?</title><link>https://community.sophos.com/thread/548894?ContentTypeID=1</link><pubDate>Thu, 21 Nov 2024 12:21:28 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:38e04ead-7c2c-4684-93a3-ecf2a0af9201</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;showing the secondary heartbeat issue:&lt;/p&gt;
&lt;p&gt;XGS4500_AM02_SFOS 21.0.0 GA-Build169 HA-Primary# tail /log/heartbeatd.log&lt;br /&gt;gr_io: Broken pipe, Offset =&amp;gt; 0&lt;br /&gt;gr_io: Resource temporarily unavailable, after retrying 5 times&lt;br /&gt;gr_io: Resource temporarily unavailable, after retrying 5 times&lt;br /&gt;gr_io: Resource temporarily unavailable, after retrying 5 times&lt;br /&gt;gr_io: Resource temporarily unavailable, after retrying 5 times&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;I think this is dangerous. Why do do these huge unzipped files remain in /log dir?&lt;/p&gt;
&lt;p&gt;Having a few of them and the disk will be full again&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;XGS4500_AM02_SFOS 21.0.0 GA-Build169 HA-Primary# ls -lhS ips.*&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24.4G Nov 21 11:22 ips.log-20241121_111359&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.0G Nov 21 13:47 ips.log&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.3G Nov 21 13:46 ips.log-20241121_134627&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 185.0M Nov 21 13:40 ips.log-20241121_134007.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 169.3M Nov 21 13:43 ips.log-20241121_134303.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 157.1M Nov 21 13:32 ips.log-20241121_133215.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 145.8M Nov 21 13:37 ips.log-20241121_133715.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 142.5M Nov 21 13:34 ips.log-20241121_133445.gz&lt;br /&gt;#logrotate#&lt;br /&gt;XGS4500_AM02_SFOS 21.0.0 GA-Build169 HA-Primary# ls -lhS ips.*&lt;br /&gt;&lt;strong&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24.4G Nov 21 11:22 ips.log-20241121_111359&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.3G Nov 21 13:46 ips.log-20241121_134627&lt;/strong&gt;&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 306.3M Nov 21 13:47 ips.log&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 185.0M Nov 21 13:40 ips.log-20241121_134007.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 169.3M Nov 21 13:43 ips.log-20241121_134303.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 157.1M Nov 21 13:32 ips.log-20241121_133215.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 145.8M Nov 21 13:37 ips.log-20241121_133715.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 142.5M Nov 21 13:34 ips.log-20241121_133445.gz&lt;br /&gt;-rw-r--r--&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34.1M Nov 21 13:47 ips.log-20241121_134627.gz&lt;br /&gt;XGS4500_AM02_SFOS 21.0.0 GA-Build169 HA-Primary# date&lt;br /&gt;Thu Nov 21 13:47:33 CET 2024&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>