USG FLEX 500H - Logs broken AGAIN

Mk88_it
Mk88_it Posts: 73 image  Ally Member
First Comment Friend Collector Third Anniversary
edited September 30 in USG FLEX H Series

Hello, the logs on our 500H are broken again, even with the latest firmware 1.35(ABZH.2) as you can see in the following picture

image.png

There is also a previous question tha has already been answered by @Zyxel_Judy
V1.32 500H: the logs are broken — Zyxel Community

All Replies

  • PeterUK
    PeterUK Posts: 4,078 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited September 30

    Logs and time seems fine here can you check in USG system > settings the time is correct to windows?

    I also use windows as a time server for my USG

    ConfigureNTP Server in Windows Server 2019/2022 | ComputingForGeeks

    You will also need this set on the USG by SSH

    edit running
    vrf main ntp maxdistance 16
    commit
    copy running startup
  • Mk88_it
    Mk88_it Posts: 73 image  Ally Member
    First Comment Friend Collector Third Anniversary

    @PeterUK The logs and time aren't fine unfortunately…. The logs are stopped since one day after the last boot of the device

    image.png image.png image.png

    We had the same issue with firmware version 1.32 too

  • PeterUK
    PeterUK Posts: 4,078 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Seems fine here like I said time matches in real time

    I suggest you test setting up windows as a NTP server and see if that makes difference?

    I know that with these FLEX H they send logs to nebula maybe your not linking to the servers correctly and its causing a problem? I know that I'm in a case where the USG fail to connect to server sometimes.

    Do you have many WAN IP uplinks?

    Screenshot 2025-09-30 172941.png Screenshot 2025-09-30 173001.png
  • Mk88_it
    Mk88_it Posts: 73 image  Ally Member
    First Comment Friend Collector Third Anniversary

    I don't know why, but the logs feature is completely stopped on our device. I don't think it's a problem about NTP or wan config

    No logs are sent to Nebula or SecuReporter either.

    I know how to solve the situation: reboot the device as usual 😫

    @Zyxel_Melen @Zyxel_Judy Would you like to investigate this issue? If not, I will have to reboot the device….

    image.png image.png
  • Zyxel_Melen
    Zyxel_Melen Posts: 3,881 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Mk88_it

    PM sent. Please help to provide the org and site name and enable Zyxel support. Thanks!

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,078 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    One thing I'm doing different to most people is the following:

    make group with the following FQDN

    *.myzyxel.com
    *.zyxel.com

    then make a routeing rule

    incoming Zywall

    Destination Address FQDN group you made

    nexp hop your WAN interface

    SNAT none

    then reboot see if that fixes it

  • Dylan96
    Dylan96 Posts: 35 image  Freshman Member
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security First Comment Friend Collector

    I don't think this solution is relevant to the problem described.

  • PeterUK
    PeterUK Posts: 4,078 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Well it still the fact that I don't see this problem so must be doing something different if the USG is not connecting to Nebula maybe thats the reason why log locally are not happening in time.

  • Mk88_it
    Mk88_it Posts: 73 image  Ally Member
    First Comment Friend Collector Third Anniversary

    I think it's something related to device insight function

  • PeterUK
    PeterUK Posts: 4,078 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    well I do have that disabled so you might be right?