Built-in firewall action filter fails to capture TCP strict drop logs for NSX-T
search cancel

Built-in firewall action filter fails to capture TCP strict drop logs for NSX-T

book

Article ID: 452627

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Searching for dropped packets using vmw_nsxt_firewall_action filter fails to capture TCP strict drops because the NSX Content Pack lacks the required regex pattern, yielding incomplete results.

Environment

Aria Operations for Logs 8.18.x

Cause

This issue occurs because the filter's pre-context regular expression does not account for the tcp strict string present in specific firewall log lines.

 Pre-context regular expression (?:match|TERM|L7 Rule pending)

Resolution

This issue is under review with Broadcom Engineering. The fix will be implemented in the upcoming NSX-T Content Pack.

Subscribe to the article to receive updates.