How to collect tech-support logs with user specific information?

Aruba Employee
Q:

How to collect tech-support logs with user specific information? 
 



A:

The usual tech-support logs are collected using the command "tar logs tech-support" that contains the controller logs and the tech-support file with a set of show commands. 

A user specific tech-support logs contains addition show commands in the tech-support file that are specific to the given user MAC / IP address. 

For a client with MAC address 38:59:f9:e0:de:c2 and IP address 20.20.20.205, the user specific tech-support logs can be collected as below.  

(Rajaguru-6.4.3.9) #show user-table

Users
-----
    IP             MAC            Name     Role           Age(d:h:m)  Auth  VPN link  AP name  Roaming   Essid/Bssid/Phy                       Profile        Forward mode  Type  Host Name
----------    ------------       ------    ----           ----------  ----  --------  -------  -------   ---------------                       -------        ------------  ----  ---------
20.20.20.205  38:59:f9:e0:de:c2            CRYSTAL-PSK-2  00:00:03                    AP-135   Wireless  CRYSTAL-PSK-2/6c:f3:7f:af:69:83/g-HT  CRYSTAL-PSK-2  tunnel

User Entries: 1/1
 Curr/Cum Alloc:1/2 Free:0/1 Dyn:1 AllocErr:0 FreeErr:0


(Rajaguru-6.4.3.9) #tar logs tech-support user mac 38:59:f9:e0:de:c2 ?
<cr>

(Rajaguru-6.4.3.9) #tar logs tech-support user mac 38:59:f9:e0:de:c2
This operation may take a while, Please do not power cycle the box

 

The tech-support log file will be saved in the flash in the name logs.tar (same name as the usual tech-support logs)  

(Rajaguru-6.4.3.9) #dir

-rw-r--r--    1 root     root        36254 Jul 25 20:47 default.cfg
drwxr-xr-x    3 root     root         4096 Jul 11 19:19 fieldCerts
-rw-r--r--    1 root     root      5129728 Jul 25 20:51 logs.tar
drwx------    2 root     root         4096 Jul 11 19:19 tpm

 

The logs can be copied to a TFTP server using the below command where 20.20.20.204 is the IP address of the TFTP server. 

(Rajaguru-6.4.3.9) #copy flash: logs.tar tftp: 20.20.20.204 User-TechSupport-Logs.tar 

 

If we need only the tech-support file instead of the complete logs, it can be collected as below. 

(Rajaguru-6.4.3.9) #show tech-support user mac 38:59:f9:e0:de:c2 ?
<filename>              Store output in file:Maximum length of file name is
                        127 chars
|                       Output Modifiers
<cr>

(Rajaguru-6.4.3.9) #show tech-support user mac 38:59:f9:e0:de:c2 Show-User-TechSupport.log 

 

The file will be saved in the flash in the name we specified.  

(Rajaguru-6.4.3.9) #dir

-rw-r--r--    1 root     root      1759704 Jul 25 21:00 Show-User-TechSupport.log
-rw-r--r--    1 root     root        36254 Jul 25 20:47 default.cfg
drwxr-xr-x    3 root     root         4096 Jul 11 19:19 fieldCerts
-rw-r--r--    1 root     root      5129728 Jul 25 20:51 logs.tar
drwx------    2 root     root         4096 Jul 11 19:19 tpm 

 

The tech-support file can be copied to a TFTP server using the below command where 20.20.20.204 is the IP address of the TFTP server.  

(Rajaguru-6.4.3.9) #copy flash: Show-User-TechSupport.log tftp: 20.20.20.204 Show-User-TechSupport.log 

 

The user specific tech-support file or logs contains the outputs of the below show command for the MAC 38:59:f9:e0:de:c2 / IP 20.20.20.205. 

===========Running user specific commands==========

show aaa state station 38:59:f9:e0:de:c2  
show ap association client-mac 38:59:f9:e0:de:c2  
show auth-tracebuf mac 38:59:f9:e0:de:c2  
show aaa debug vlan user mac 38:59:f9:e0:de:c2  
show datapath bridge table 38:59:f9:e0:de:c2  
show ap debug client-stats 38:59:f9:e0:de:c2 advanced  
show wms client 38:59:f9:e0:de:c2  
show station-table mac 38:59:f9:e0:de:c2  
show aaa device-id-cache mac 38:59:f9:e0:de:c2  
show ip mobile binding 38:59:f9:e0:de:c2  
show ip mobile host 38:59:f9:e0:de:c2  
show ip mobile remote 38:59:f9:e0:de:c2  
show ip mobile trace 38:59:f9:e0:de:c2  
show ip mobile trail 38:59:f9:e0:de:c2  
show ip mobile visitor 38:59:f9:e0:de:c2  
show wms client probe  38:59:f9:e0:de:c2  
show ap virtual-beacon-report client-mac 38:59:f9:e0:de:c2  
show arp | include Protocol,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show datapath route-cache table | include Route,---,Flags,Temp,IP,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show datapath station table | include Datapath,----,Flags,AMSDU,MAC,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show datapath user table | include Datapath,----,Flags,VPN,Src,IP,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show user-table verbose | include Users,---,IP,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show dot1x supplicant-info list-all | include 802,----,MAC,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show dot1x supplicant-info statistics | include 802,----,Mac,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show log all | include 38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show wms client list | include Station,----,Monitor,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show user-table ip 20.20.20.205  
show aaa state user 20.20.20.205  
show datapath  session table 20.20.20.205  
show ap debug client-table ap-name AP-135 | include Client,----,MAC,UAPSD,Flags,Delayed,Station,STBC,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show datapath bridge ap-name AP-135 | include Datapath,---,Permanent,Awaiting,MAC,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show datapath route-cache ap-name AP-135 | include Route,----,Flags,trusted,Temp,IP,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show datapath user ap-name AP-135 | include Datapath,----,Flags,VPN,Src,Split,IP,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap arm bandwidth-management ap-name AP-135 |  include 38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap debug log  ap-name AP-135 | include 38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap monitor client-list ap-name AP-135 | include Monitored,---,mac,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap monitor ids-state ap-name AP-135 events | include Intrusion,---,Time,38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap arm client-match probe-report ap-name AP-135 |  include 38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap arm client-match restriction-table ap-name AP-135 |  include 38:59:f9:e0:de:c2,38:59:F9:E0:DE:C2,38:59:f9:e0:de:c2  
show ap remote debug mgmt-frames ap-name AP-135  
show rights CRYSTAL-PSK-2  
show datapath session ap-name AP-135 table 20.20.20.205  

 

Version history
Revision #:
2 of 2
Last update:
‎03-29-2017 12:00 PM
Updated by:
 
Labels (1)
Contributors
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: 
Is this a frequent problem?

Request an official Aruba knowledge base article to be written by our experts.