The traces for the management server operation are written to <smc_home>/tmp/MGTSRV_YYYYMMDD_HHMMSS_xxx.txt files but in this case they won't show anything useful screenshot shows that problem happens on engine side. Based on the steps shown I would assume that you're installing policy to this NGFW engine for the first time, and now the policy you install is preventing management connection (TCP 4987 from management server to NGFW engine) from working. So what happens is that new configuration gets activated on the engine, but this prevents that management communication and thus IPS node does the rollback to previously active policy (i.e. initial configuration in this case). Most common reason for this is that routing hasn't been properly configured for IPS engine in SMC and thus when new policy gets activated, IPS does not have any valid routes in it's routing table to send packets to mgmt server.
If you can't figure this out, I would recommend opening ticket to technical support as further analysis requires getting data from the IPS engine side.
Thank you for helping. I foundthe log SMC operation are written as you mentioned.
I will check the routing configuration, and ask this to tech support as I need.