Skip to main content
Question

Difference between Advanced debugging logs and logs collected from tenant.

  • July 18, 2024
  • 2 replies
  • 242 views

Iftesam
Netskope Partner

I recently encountered the below mentioned issue and would like to have better understanding of the same.

I have collected advanced debugging logs from the users system, where in the option of “Start” for outer capture was disabled, still I collected the logs and those were as expected.

However when I tried collecting the same logs from the tenant for that user, I observed the logs were different and some of the captures which were present in the previously collected advanced debugging logs from the system were missing in the logs collected from the tenant.

Attaching the screenshots for reference:

Events triggered for the date and time : 2024/07/17 14:47:00.213

Logs collected from the tenant :

Advanced debugging logs collected from the device for the same time :

Need to understand why the captured even for the same timestamp are different.

This topic has been closed for replies.

2 replies

Forum|alt.badge.img+16
  • Netskope Employee
  • July 19, 2024

@Iftesam ,

 

I’m not sure if this is expected behavior or not.  My understanding is that  the log collection feature from the tenant should zip up the same log files and upload them to Netskope.  I’d suggest opening a support case for support and/or engineering to validate if this is behaving as expected and troubleshoot further. 

 


Iftesam
Netskope Partner
  • Author
  • Netskope Partner
  • July 20, 2024

@sshiflett 

Thanks for the update!