This article contains instructions for troubleshooting your SRX device. It includes common commands for monitoring, viewing log files, and configuring traceoptions and packet capture. For other topics, go to the SRX Getting Started main page.
Troubleshooting SRX Series devices.
This section contains the following:
Command Description show version Software version show chassis hardware detail Hardware and Serial numbers show chassis environment Temperatures, Fan and Power Supply show chassis routing-engine Temperatures, Memory, CPU Load show interfaces terse Interface States show interfaces extensive Interface and Zone Counters monitor interface <interface_name> Real-time interface statistics <interface_name> show security flow session Current sessions show system alarms show chassis alarms Alarms
show version
show chassis hardware detail
show chassis environment
show chassis routing-engine
show interfaces terse
show interfaces extensive
monitor interface <interface_name>
show security flow session
show system alarms show chassis alarms
Command Description show log List all Logfiles available show log messages Show Log File from beginning show log messages | last List last Log Messages show log messages | match LOGIN Search within the Log monitor start <file> Send Logs to terminal (like tail -f)
KB16108 - Configuring Traceoptions for Debugging, and Trimming Output [juniper.net] KB16233 - How to use 'Flow Traceoptions' and the 'security datapath-debug' [juniper.net]
Note: The Packet Capture Feature can also be used to capture 'self-traffic' (e.g. Dynamic Routing Protocol messages, ARP, management traffic, ICMP to Routing Engine). However, this Packet Capture feature is not available on the SRX High-End devices.
datapath-debug
> monitor traffic interface <int> layer2-headers > monitor traffic interface e1-0/0/0.0 no-resolve