While downloading the Sky ATP Security Intelligence Manifest, the SRX device reports the "JSF-SECINTEL: Black List Compilation Failed" syslog message.
This article explains why the syslog error message may be reported and what should be done to resolve the error.
Customers may notice that their users are not getting blocked by the configured Blocklist URL/Domain entries. In addition to this, the following syslog message is reported by the SRX device while downloading the Sky ATP Security Intelligence Manifest.
JSF-SECINTEL: Black List Compilation Failed
There may be multiple services running on the SRX platform due to which there is possible contention for system resources. Depending on the database resources used for URL and Domain Blocklists, the SRX device may not be able to deserialize all URL or Domain Blocklist entries from the Routing Engine to the Packet Forwarding Engine, which results in the "JSF-SECINTEL: Black List Compilation Failed" error.
This error is not based on the Security Intelligence Manifest download between the SRX device and the Policy Enforcer or Sky ATP. The error may be triggered when the SRX Routing Engine copies the manifest to its PFE.
Depending on the type of device (that is SRX340 or SRX5400) and the available resources, lower the number of URL or Domain Blocklist entries for the specific device to avoid running into the above error.
2021-03-25: Updated the article terminology to align with Juniper's Inclusion & Diversity initiatives.