This document describes how to inspect the pd_info directory and bootuplog file from a system report in order to troubleshoot unexpected reloads.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
This document is based on enterprise routing and switching Cisco IOS® XE platforms. When decompressing the system report generated upon an unexpected reload of a Cisco IOS XE device, it contains a directory called pd_info under the bootflash directory and the bootuplog file under the tmp directory.
Note: Refer to system report documentation at System reports.
The pd_info directory refers to the platform dependent information and it contains generally these log files:
Note: Note that every log file has a date and time stamp as part of the file name.
Some of these files helps to understand the last conditions in terms of resources before a device reloaded unexpectedly.
This document focuses in a brief explanation of some of these files.
pd_info Directory
This section describes different files contains within the pd_info directory from a system report.
The two log files are:
Note: This output corresponds with the output of command show platform software mount which is described at Cisco IOS Configuration Fundamentals Command Reference.
An example output can be seen here:
**********************************
OUTPUT OF df -h
**********************************
Filesystem Size Used Avail Use% Mounted on
rootfs 7.7G 136M 7.5G 2% /
devtmpfs 4.0M 0 4.0M 0% /dev
tmpfs 7.7G 9.6M 7.7G 1% /dev/shm
tmpfs 3.1G 9.6M 3.1G 1% /run
tmpfs 4.0M 0 4.0M 0% /sys/fs/cgroup
tmpfs 7.7G 79M 7.6G 2% /tmp
tmpfs 7.7G 360K 7.7G 1% /var
tmpfs 5.0M 40K 5.0M 1% /var/log/audit
/dev/sda2 1008M 1.3M 956M 1% /flash6
/dev/sda4 7.8M 346K 7.1M 5% /flash4
/dev/sda5 7.8M 58K 7.3M 1% /flash5
/dev/sda6 124M 1.6M 116M 2% /flash3
/dev/sda7 1.2G 1.9M 1.2G 1% /flash7
/dev/sda1 1.6G 263M 1.3G 18% /flash2
/dev/sda3 11G 2.5G 7.6G 25% /flash1
/dev/loop0 32K 32K 0 100% /tmp/sw/mount/cat9k-wlc.17.09.04a.SPA.pkg
/dev/loop1 2.1M 2.1M 0 100% /tmp/sw/mount/cat9k-guestshell.17.09.04a.SPA.pkg
/dev/loop2 18M 18M 0 100% /tmp/sw/mount/cat9k-webui.17.09.04a.SPA.pkg
/dev/loop3 26M 26M 0 100% /tmp/sw/mount/cat9k-cc_srdriver.17.09.04a.SPA.pkg
/dev/loop4 40M 40M 0 100% /tmp/sw/mount/cat9k-srdriver.17.09.04a.SPA.pkg
/dev/loop5 50M 50M 0 100% /tmp/sw/mount/cat9k-sipbase.17.09.04a.SPA.pkg
/dev/loop6 63M 63M 0 100% /tmp/sw/mount/cat9k-sipspa.17.09.04a.SPA.pkg
/dev/loop7 166M 166M 0 100% /tmp/sw/mount/cat9k-espbase.17.09.04a.SPA.pkg
/dev/loop8 781M 781M 0 100% /tmp/sw/mount/cat9k-rpbase.17.09.04a.SPA.pkg
tmpfs 13G 29M 13G 1% /tmp/rp/tdldb
tmpfs 13G 2.1M 13G 1% /tmp/fp/tdldb
tmpfs 13G 3.2M 13G 1% /tmp/cc/tdldb
This file output correspond to the Linux command output df -h
[Router_RP_0:/]$ df -h
Filesystem Size Used Avail Use% Mounted on
devtmpfs 4.0M 0 4.0M 0% /dev
tmpfs 3.7G 46M 3.7G 2% /dev/shm
tmpfs 1.5G 15M 1.5G 1% /run
tmpfs 4.0M 0 4.0M 0% /sys/fs/cgroup
tmpfs 3.7G 82M 3.7G 3% /tmp
/dev/bootflash1 7.2G 2.9G 4.0G 43% /bootflash
<snip>
This file snapshot is useful when troubleshooting Temporal File System (TMPFS) issues. For example, when this type of alarm is seen:
%PLATFORM-3-ELEMENT_TMPFS_WARNING: [LOCATION] R0/0: smand: [SLOT]: TMPFS value 45% above warning level 40%
memaudit.log
This file contains a different outputs regarding the memory of the system, for example:
==============================================================================
free -m
==============================================================================
total used free buffers cached
---------- ------------ ------------ ------------ ------------ ------------
Mem: 15618.812 1972.348 7662.254 5984.211 13203.898
Swap: 0.000 0.000 0.000 0.000 0.000
==============================================================================
/proc/meminfo
==============================================================================
MemTotal: 15618.812
MemFree: 7661.594
MemAvailable: 13203.746
Buffers: 503.805
Cached: 5288.754
SwapCached: 0.000
Active: 3482.742
Inactive: 3563.887
Active(anon): 1339.430
Inactive(anon): 182.828
Active(file): 2143.566
Inactive(file): 3381.059
Unevictable: 0.055
Mlocked: 0.055
SwapTotal: 0.000
SwapFree: 0.000
Dirty: 0.027
Writeback: 0.000
AnonPages: 1254.098
Mapped: 1043.117
Shmem: 267.809
KReclaimable: 192.031
Slab: 320.250
SReclaimable: 192.031
SUnreclaim: 128.219
KernelStack: 5.922
PageTables: 64.332
NFS_Unstable: 0.000
Bounce: 0.000
WritebackTmp: 0.000
CommitLimit: 7801.406
Committed_AS: 5058.414
VmallocTotal: 33554431.999
VmallocUsed: 21.395
VmallocChunk: 0.000
Percpu: 3.031
CmaTotal: 0.000
CmaFree: 0.000
HugePages_Total: 8
HugePages_Free: 8
HugePages_Rsvd: 0
HugePages_Surp: 0
Hugepagesize: 2.000
Hugetlb: 16.000
DirectMap4k: 119.438
DirectMap2M: 3646.000
DirectMap1G: 14336.000
==============================================================================
df -Th -BM
==============================================================================
Filesystem Type Blocks Used Available Use% Mounted
---------------------------------------- ---------- ------------ ------------ ------------ ---- ----------
rootfs rootfs 7785 136 7649 2 /
devtmpfs devtmpfs 4 0 4 0 /dev
tmpfs tmpfs 7810 10 7800 1 /dev/shm
tmpfs tmpfs 3124 10 3115 1 /run
tmpfs tmpfs 4 0 4 0 /sys/fs/cgroup
tmpfs tmpfs 7810 79 7731 2 /tmp
tmpfs tmpfs 7810 1 7810 1 /var
tmpfs tmpfs 5 1 5 1 /var/log/audit
<snip>
Analysis of /proc/<pid>/smaps
==============================================================================
Parent Process PID RSS PSS Shared Anon Private Siz BSiz Segs
---------- ------------------------- ------ -------- -------- -------- -------- -------- -------- -------- -----
rp linux_iosd_image 5457 829.051 677.971 236.832 310.402 592.219 7233.859 320.023 3648
fp fed 22495 266.438 224.062 65.270 167.348 201.168 4205.105 0.229 1230
rp dbm 7938 234.234 111.116 177.156 34.402 57.078 2217.719 0.538 1372
rp sessmgrd 4362 169.340 81.144 115.844 33.219 53.496 1528.961 0.211 1011
rp smand 9523 164.414 130.350 40.879 120.895 123.535 729.090 0.861 427
cc iomd 11892 138.047 127.436 16.789 36.832 121.258 2310.754 1.224 1186
rp cli_agent 8234 131.434 52.303 103.168 21.633 28.266 1150.047 0.075 742
rp fman_rp 7311 129.938 80.075 79.238 18.297 50.699 1613.012 7.553 1134
<snip>
Note: Note that the output of linux command /proc/<pid>/smaps contains Resident Set Size (RSS) value for each Cisco IOS XE process.
proc_oom_stats.log
This file can give hints about out of memory events and associated processes.
**********************************
OUTPUT OF cat /proc/oom_stats
**********************************
OOM events: 0
pid name memory
=========================================
system_report_trigger.log
This file provides an error string that indicates what event triggered the system report file generation.
top_output.log
This file contains the output of linux command top -b -n 1 -w 512 -c .
It contains relevant information about CPU and memory resources. For example:
**********************************
OUTPUT OF top -b -n 1 -w 512 -c
**********************************
top - 02:18:38 up 36 min, 0 users, load average: 0.15, 0.07, 0.17
Tasks: 322 total, 1 running, 321 sleeping, 0 stopped, 0 zombie
%Cpu(s): 0.7 us, 1.5 sy, 0.0 ni, 97.8 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st
MiB Mem : 15618.8 total, 7660.3 free, 1972.0 used, 5986.5 buff/cache
MiB Swap: 0.0 total, 0.0 free, 0.0 used. 13204.0 avail Mem
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
4028 root 20 0 6124 3312 2768 R 6.2 0.0 0:00.01 top -b -n 1 -w 512 -c
11892 root 20 0 2366212 141152 103584 S 6.2 0.9 1:45.41 /tmp/sw/cc/1/0/cc_spa/mount/usr/binos/bin/iomd -s 1 -b 0
22495 root 20 0 4306028 269572 99536 S 6.2 1.7 0:34.62 /tmp/sw/fp/0/0/fp/mount/usr/binos/bin/fed
1 root 20 0 28800 25060 8008 S 0.0 0.2 0:02.40 /init SR_PKGS_OK
2 root 20 0 0 0 0 S 0.0 0.0 0:00.00 [kthreadd]
3 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 [rcu_gp]
4 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 [rcu_par_gp]
6 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 [kworker/0:0H-kblockd]
8 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 [mm_percpu_wq]
<snip>
The bootup Log file is located in the tmp directory from the system report:
% tree sd43405-test.test_RP_0-system-report_RP_0_20260818-155012-cdt.tar.gz_decoded.log
/Users/ivanher/Downloads/sd43405-test.test_RP_0-system-report_RP_0_20260818-155012-cdt.tar.gz_decoded.log
├── bootflash
│ └── pd_info
│ ├── dmesg_output-20260818-154935-cdt.log
│ ├── filesystems-20260818-154935-cdt.log
│ ├── memaudit-20260818-154935-cdt.log
│ ├── proc_cpuinfo-20260818-154935-cdt.log
│ ├── proc_diskstats-20260818-154935-cdt.log
│ ├── proc_interrupts-20260818-154935-cdt.log
│ ├── proc_oom_stats-20260818-154935-cdt.log
│ ├── proc_softirqs-20260818-154935-cdt.log
│ ├── system_report_trigger.log
│ └── top_output-20260818-154935-cdt.log
├── btracedecode.log
├── crashinfo
│ └── tracelogs
│ ├── IOSRP_R0-0.7286_0.20260714192115.bin.gz_decoded.log
<snip>
├── flash
│ └── core
│ └── test-test_RP_0_cman_fp_12978_20260818-154932-cdt.core.gz
└── tmp
├── cc
│ ├── 0
│ │ └── trace
│ │ └── cmcc_0-0.10584_0.20260714192102.bin_decoded.log
<snip>
├── cyan
│ └── cyan.log
├── fp
<snip>
├── maroon_stats
│ ├── btman_cc_1_18392.maroon
<snip>
├── rp
<snip>
│ └── trace
│ ├── IOSRP_R0-0.7286_79.20260818204252.bin_decoded.log
<snip>
├── silent_roll_select.log
├── tdlresolve
│ └── epoch_dir
│ ├── 2026_07_14_19_21_6031.epoch
│ ├── active
│ ├── rp0current
│ └── rp1current
├── test_RP_0-bootuplog-20260818-155012-cdt.log <<<<<<<<<<<<<<<<<<<<<<< bootuplogfile
├── udev_ng4k.vbd.log
└── vbd_app_init.log
776 directories, 2646 files
This file contains some logs that can be relevant to understand an unexpected reset.
For example, it can contain if there were heartbeat misses for multicard systems:
Aug 18 15:49:32 test_RP_0 cman_fp[12978]: %CMFP-3-HB_TIMEOUT: F0/0: cman_fp: Peroidic Heartbeat message from RP timed out.
Aug 18 15:49:34 test_RP_0 pman:[10638]: %PMAN-3-PROCHOLDDOWN: F0/0: pman: The process cman_fp has been helddown (rc 134)
In wireless controllers (for example the Cisco Catalyst 9800) it contains data about last activity happening in a High Availability (HA) environment:
Jul 27 11:35:37 test_2_RP_0 rif_mgr[6455]: %RIF_MGR_FSM-6-RP_LINK_UP: R0/0: rif_mgr: The RP link is UP.
Jul 27 11:35:37 test_2_RP_0 stack_mgr[5465]: %STACKMGR-1-DUAL_ACTIVE_CFG_MSG: R0/0: stack_mgr: Dual Active Detection link is available now
Jul 27 11:35:38 test_2_RP_0 wncmgrd[17474]: %EWLC_HA_LIB_MESSAGE-6-BULK_SYNC_STATE_INFO: R0/0: wncmgrd: INFO: Bulk sync status : CONFIG_DONE
Jul 27 11:35:38 test_2_RP_0 ndbmand[26588]: %NDBMAN-5-ACTIVE: R0/0: ndbmand: All data providers active.
Jul 27 11:35:39 test_2_RP_0 stack_mgr[5465]: %STACKMGR-6-KA_MISSED: R0/0: stack_mgr: Keepalive missed for 2 times for Chassis 1
Jul 27 11:35:40 test_2_RP_0 stack_mgr[5465]: %STACKMGR-6-CHASSIS_REMOVED: R0/0: stack_mgr: Chassis 1 has been removed from the stack.
Jul 27 11:35:40 test_2_RP_0 stack_mgr[5465]: %STACKMGR-6-CHASSIS_REMOVED_KA: R0/0: stack_mgr: Chassis 1 has been removed from the stack due to keepalive failure.
The log file bootuplog.log is also included in the system report, in the tmp directory. This log file contains relevant logs which can be useful to have more visibility about last logs seen by the system before an unexpected reload.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
30-Sep-2026
|
Initial Release |