<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot add user to Security Rule by API in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/cannot-add-user-to-security-rule-by-api/m-p/290704#M2041</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33914"&gt;@dbatrankov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed similar behavior in the past. Try to type the username manually in the rule base and commit it. See if you can see logs for that security rule.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2019 03:26:02 GMT</pubDate>
    <dc:creator>Rajesh12</dc:creator>
    <dc:date>2019-10-01T03:26:02Z</dc:date>
    <item>
      <title>Cannot add user to Security Rule by API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/cannot-add-user-to-security-rule-by-api/m-p/290611#M2040</link>
      <description>&lt;P&gt;There is a good example how to add user by API&lt;/P&gt;&lt;P&gt;&lt;A href="http://api-lab.paloaltonetworks.com/groups.html#example-add-user-to-group-mappings-groups" target="_blank" rel="noopener"&gt;http://api-lab.paloaltonetworks.com/groups.html#example-add-user-to-group-mappings-groups&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I put the XML from the example to&amp;nbsp;&lt;A href="https://192.168.1.100/php/rest/browse.php/user-id" target="_blank" rel="noopener"&gt;https://192.168.1.100/php/rest/browse.php/user-id&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;uid-message&amp;gt;&lt;BR /&gt;&amp;lt;version&amp;gt;2.0&amp;lt;/version&amp;gt;&lt;BR /&gt;&amp;lt;type&amp;gt;update&amp;lt;/type&amp;gt;&lt;BR /&gt;&amp;lt;payload&amp;gt;&lt;BR /&gt;&amp;lt;login&amp;gt;&lt;BR /&gt;&amp;lt;entry name="domain\user1" ip="192.168.1.50" /&amp;gt;&lt;BR /&gt;&amp;lt;/login&amp;gt;&lt;BR /&gt;&amp;lt;groups&amp;gt;&lt;BR /&gt;&amp;lt;entry name="group1"&amp;gt;&lt;BR /&gt;&amp;lt;members&amp;gt;&lt;BR /&gt;&amp;lt;entry name="user1" /&amp;gt;&lt;BR /&gt;&amp;lt;entry name="domain\user2" /&amp;gt;&lt;BR /&gt;&amp;lt;/members&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;entry name="group2"&amp;gt;&lt;BR /&gt;&amp;lt;members&amp;gt;&lt;BR /&gt;&amp;lt;entry name="user3" /&amp;gt;&lt;BR /&gt;&amp;lt;/members&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;/groups&amp;gt;&lt;BR /&gt;&amp;lt;/payload&amp;gt;&lt;BR /&gt;&amp;lt;/uid-message&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then it works well:&lt;/P&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;response&lt;SPAN class="html-attribute"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-attribute-name"&gt;status&lt;/SPAN&gt;="&lt;SPAN class="html-attribute-value"&gt;success&lt;/SPAN&gt;"&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="collapsible-content"&gt;&lt;DIV class="collapsible"&gt;&lt;DIV class="expanded"&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;result&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="collapsible-content"&gt;&lt;DIV class="collapsible"&gt;&lt;DIV class="expanded"&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;uid-response&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="collapsible-content"&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;version&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="text"&gt;2.0&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/version&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;payload&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="text"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/payload&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/uid-response&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/result&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/response&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;admin@PA-220&amp;gt; show user ip-user-mapping all&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;IP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Vsys&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;From&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;User &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;IdleTimeout(s) MaxTimeout(s)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;--------------------------------------------- ------------------- ------- -------------------------------- -------------- -------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;192.168.1.50&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;vsys1 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;XMLAPI&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;domain\user1 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;2696 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;2696&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Total: 1 users&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p2"&gt;But I cannot see this user "domain\user1" from security policy rule. Why? I see only group name.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cannot get username to the list" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21594i7185B9D9D92BE0E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Снимок экрана 2019-09-30 в 19.07.18.png" alt="Cannot get username to the list" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Cannot get username to the list&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 16:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/cannot-add-user-to-security-rule-by-api/m-p/290611#M2040</guid>
      <dc:creator>dbatrankov</dc:creator>
      <dc:date>2019-09-30T16:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add user to Security Rule by API</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/cannot-add-user-to-security-rule-by-api/m-p/290704#M2041</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33914"&gt;@dbatrankov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed similar behavior in the past. Try to type the username manually in the rule base and commit it. See if you can see logs for that security rule.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 03:26:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/cannot-add-user-to-security-rule-by-api/m-p/290704#M2041</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2019-10-01T03:26:02Z</dc:date>
    </item>
  </channel>
</rss>

