In SmartDashboard, the "Hits" counter in a specific rule does not increase even though traffic was matched to this rule
||R75, R76, R77, R77.10, R77.20, R77.30
|Platform / Model
In SmartDashboard, the "Hits" counter in a specific rule does not increase even though traffic was matched to this rule (as can be seen in SmartView Tracker / SmartLog / SmartEvent).
After a number of days, this rule appears in the expired rules, because the Hit Count table is not being updated.
Possible root cause on Security Gateway:
- By default, Hit Count logs table (updated by the FWD daemon) holds up to 100 records (a record per rule).
- When the above limit is reached, writing to this table is blocked.
- When the first log is written to the Hit Count logs table, there is a time event for updating the Hit Count (CPEPS) table (by default, 1 minute).
- If update of the Hit Count table (CPEPS) failed (e.g., when CPD daemon is down), there is no indication on the Hit Count statistics mechanism.
- If the limit in Hit Count logs table is reached, and the update of the Hit Count table (CPEPS) failed, then the entire process could be stuck in State B and could not recover.
Note: To view this solution you need to