This document lists what information should be collected when there is a problem on one of the following Juniper devices running IDP (Intrusion Detection and Prevention):
What information should I collect to assist in troubleshooting prior to opening a case? The goal of this document is to reduce the time spent on initial data collection and reduce time to resolve by providing a comprehensive list of what to collect or gather to troubleshoot an issue.
Collect the following data for your device. Either attach the data to your case or securely transfer the data using these instructions: KB23337 - How to upload large files to a JTAC Case [juniper.net]
/var/idp/device/corefiles
cd /var/idp/device/sysinfo
tar -cf logs_archive logs
request support information | no-more - Log your SSH session and enter this in operational mode at the Junos CLI to pull the configuration and statistics from the time it was requested. show system core-dumps - Enter this command in operational mode at the Junos CLI to see if core dumps were generated. If core dumps are present, then collect those.
root@host> start shell root@host% cd /var/log root@host% tar -cf varlogs.tar *
exec sm 3 ksh "ls -l /idp/log
# exec sm <#> save tftp <tftp-ip> <filename>
/idp/log/engine.core
# exec sm # ksh "sloginfo