> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md).

# Access logs and log bundles

Logs provide information about events that occur in the system. They are a valuable tool in troubleshooting issues that might arise in your Cortex XSOAR environment. If you need additional help to find the source of an issue, you can download the log bundle to send to support or engineering or to attach to a support ticket to facilitate the troubleshooting process.

{% hint style="info" %}

### Note

You need **viewer** SSH user permissions to view and download logs.
{% endhint %}

Once Cortex XSOAR is installed and running, you can view system status and download log bundles from the Cortex XSOAR UI. If you encounter issues during installation or if Cortex XSOAR is not running, you can access logs and log bundles from the textual UI menu.

#### View logs and download log bundles from the textual UI

1. If the textual UI is not already open, either launch the web console from your VM or SSH log in from an external terminal. For more information, see [Troubleshoot your installation](/cortex-xsoar-8-on-prem/8.12/install-cortex-xsoar/troubleshoot-your-installation.md).

   ![](/files/3ZPna8mlRaBJjz3HY3T1)
2. To see the logs, in the textual UI menu, select **View Logs**.

   These logs are not related to any user session in Cortex XSOAR.
3. To download a log bundle, in the textual UI menu, select **Log Bundle**.

   The **viewer** user can use scp/sftp to download the log bundle to their home directory.

#### View system status and download log bundles from Cortex XSOAR

1. In Cortex XSOAR, navigate to Settings & Info → **System** → **System Diagnostics**.

   The **System Diagnostics** page provides system status data over time in the form of graph and table widgets.

   ![](/files/ojSdHpdWsGchNC9FDDT7)

<details>

<summary>System status details</summary>

The graphs and tables in the System Diagnostics page show the following data. This information can help troubleshoot system performance issues. If you need additional help to find the source of the issue, you can download the log bundle to send to support or engineering or to attach to a support ticket.

| Widget                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Nodes - CPU                  | A trend graph showing CPU consumption. The graph shows an increase as system usage increases. Temporary peaks may indicate system delays or slowness. We recommend increasing CPU resources when you reach system limits.                                                                                                                                                                                                                                                                                                                                                       |
| Active Nodes Snapshot        | A list of all active nodes and their statuses. Possible values are Connected or Disconnected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Storage Groups               | A trend graph showing storage group utilization. The graph shows an increase as storage usage increases. A rapid surge in storage utilization may indicate a change in system usage. We recommend either increasing storage capacity or performing a data cleanup when utilization reaches 80%.                                                                                                                                                                                                                                                                                 |
| Nodes Memory                 | A trend graph showing memory consumption. The graph shows an increase as memory usage increases. Temporary peaks may indicate system delays or slowness. We recommend increasing memory resources when you reach system limits.                                                                                                                                                                                                                                                                                                                                                 |
| XSOAR Components Snapshot    | <p>A table showing the status of Cortex XSOAR components. Possible values are Healthy, Warning, or Error.</p><p>If you see a warning or error for a Cortex XSOAR component, we recommend you:</p><ul><li>Check cluster health graphs for temporary peaks or high resource utilization.</li><li>Check storage utilization graphs.</li><li>If you have recently made changes to your system, verify if these changes have impacted system components.</li><li>Open a support case if you cannot find the source of the issue.</li></ul>                                           |
| Playbooks in Queue           | <p>A graph that includes both manually triggered and automatically triggered playbooks and displays how many playbooks were waiting in the queue over the displayed time period.</p><p>Playbook queues manage playbook executions efficiently and prevent system overload. Rapid surge in the graph values may indicate a temporary peak of triggered playbooks that can cause playbooks to take longer to execute and/or slow UI performance.</p><p>If the queue count is consistently higher than 0, we recommend contacting customer support to discuss scaling options.</p> |
| Nodes - Storage              | A trend graph showing storage usage. The graph shows an increase as storage usage increases. Temporary peaks may indicate system delays or slowness. We recommend increasing storage resources when you reach system limits.                                                                                                                                                                                                                                                                                                                                                    |
| Cortex Connectivity Snapshot | <p>A table showing the status of the connection between your Cortex XSOAR local tenant and the external gateway.</p><p>If the status is Disconnected, you cannot upgrade Cortex XSOAR, access Marketplace, or update Docker images.</p>                                                                                                                                                                                                                                                                                                                                         |

<br>

</details>

<details>

<summary>Select the timeframe for the system status data</summary>

You can choose the following time frames to display the system status data:

* Last hour
* Last 6 hours
* Last 12 hours
* Last 24 hours (Default)
* Last 3 days
* Last 7 days

</details>

2. To download a log bundle, from the System Diagnostics page click [![opp-download-log-bundle.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACIAAAAlCAYAAAAnQjt6AAAACXBIWXMAABJ0AAASdAHeZh94AAAAB3RJTUUH6AoKDA8eZ0MTQgAAAhBJREFUWIXtl82rMWEYh3++h42PaUQj1CyVtYVsJPk7ZqXYjbEWS0rYspr/QEJJylosJlYWysLOSj6SeRdvZ3pzfMwcx3mdcu3ueX51X/Xcz9MzGkmSJLwA2v8t8MFb5JyXEdErDc7ncxSLRZAkCZ1Op7jBdrtFNBpFPB5/XEQURdTrddhsNiSTSdA0rVhkOp2i1+vdFbm7NePxGI1GAxzHweFwQO1p1+v1OJ1O93O3FgeDAVqtFnieh8vlUiWglqsi7XYbw+EQPM+DoigAwGazgdlsVtVAo9E8JtLtdmG1WlGr1eRvHo8HJEn+rIjFYkEul1PV9BJK5gP4jfcIAEwmExyPx4trXq8XTqfzZ0RGo9FVEYPB8HMiLMt+udE9VImk02ns9/ubGYIgUKlU5Nrn8yEWi32vSLVaVRMHAJhMJgQCge8VuTWsAGC328EwjFzvdjuIoijXNE3D7XY/LnJrWIG/J+dfkU6ng0KhINfhcBjlcvlxkV8zrMFgEKlU6vkiXxlWpbzMFf8WOUdz7U8vk8mAYRjF74kPQqEQ1us1OI67mkkkEsjn88pEVqsVlsulKgkAoCgKXq8X2WwW/X7/4rogCJ8eWFdFHuVwOIBlWcxmM/kbQRAQBAF+v/9T/mkzYjQaUa1W5Stdq9WiVCpdlAAASE9msVhIkUhEajabN3NP2xq1vMzxfYuc8xY55w8eByqrGmTGzAAAAABJRU5ErkJggg==)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/7RGnhrYBoC8zHRVnKsOM5A/2EIwWc_1O8CFIUpP_zpwig-7RGnhrYBoC8zHRVnKsOM5A).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.12/troubleshoot-and-reference/troubleshoot/access-logs-and-log-bundles.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
