<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic log source user different from User-ID log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593690#M118167</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315823"&gt;@EdmarFrancis&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since deleting the local fw fixed the issue, it could be a User-ID cache issue. You can try running a command like "&lt;SPAN class="hljs-attribute"&gt;clear&lt;/SPAN&gt; user-cache &lt;SPAN class="hljs-attribute"&gt;all" next time to see if it fixes the issue.&amp;nbsp;The User-ID cache on the fw might have had stale or incorrect entries, causing the local firewall account to be shown in the traffic log.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2024 18:09:07 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2024-07-31T18:09:07Z</dc:date>
    <item>
      <title>Traffic log source user different from User-ID log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593285#M118076</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;PA-1410&lt;BR /&gt;11.0.4-h1&lt;BR /&gt;&lt;BR /&gt;I have a bit odd issue, the traffic log (ip address) is showing a local firewall account as the source user but when checking the user-mapping (show user ip-user-mapping ip) or User-ID log was mapped to an AD-user. &lt;BR /&gt;&lt;BR /&gt;Is it possible for the local firewall account to show as a source user?&lt;BR /&gt;is it possible that this is just a GUI bug? &lt;BR /&gt;&lt;BR /&gt;deleted the local firewall account and seems to have the issue fixed.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 08:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593285#M118076</guid>
      <dc:creator>EdmarFrancis</dc:creator>
      <dc:date>2024-07-29T08:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic log source user different from User-ID log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593690#M118167</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315823"&gt;@EdmarFrancis&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since deleting the local fw fixed the issue, it could be a User-ID cache issue. You can try running a command like "&lt;SPAN class="hljs-attribute"&gt;clear&lt;/SPAN&gt; user-cache &lt;SPAN class="hljs-attribute"&gt;all" next time to see if it fixes the issue.&amp;nbsp;The User-ID cache on the fw might have had stale or incorrect entries, causing the local firewall account to be shown in the traffic log.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 18:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593690#M118167</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-07-31T18:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic log source user different from User-ID log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593727#M118177</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt; , thanks for your response. did try to delete the cache (&lt;SPAN class="collab-selectable-content-wrapper" data-test-desctext="" data-test-selectablecontent=""&gt;&lt;EM&gt;clear user-cache ip&lt;/EM&gt;&lt;/SPAN&gt; xx.xx) but same. It seems to be legitimate traffic. &lt;BR /&gt;Per my understanding the local firewall user is able to show as source user when for example used to authenticate to GlobalProtect app or Captive portal, is that right?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 05:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/593727#M118177</guid>
      <dc:creator>EdmarFrancis</dc:creator>
      <dc:date>2024-08-01T05:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic log source user different from User-ID log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/594160#M118244</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315823"&gt;@EdmarFrancis&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;BR /&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;PA-1410&lt;BR /&gt;11.0.4-h1&lt;BR /&gt;&lt;BR /&gt;I have a bit odd issue, the traffic log (ip address) is showing a local firewall account as the source user but when checking the user-mapping (show user ip-user-mapping ip) or User-ID log was mapped to an AD-user. &lt;BR /&gt;&lt;BR /&gt;Is it possible for the local firewall account to show as a source user?&lt;BR /&gt;is it possible that this is just a GUI bug? &lt;BR /&gt;&lt;BR /&gt;deleted the local firewall account and seems to have the issue fixed.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315823"&gt;@EdmarFrancis&lt;/a&gt;&amp;nbsp;I know you mentioned deleting a user fixed your issue, but i have hit a user ID bug where the IP to user-id mapping was wrong.&amp;nbsp; It was identified as&amp;nbsp;PAN-239366 which is fixed in these versions:&amp;nbsp; "11.2.0,&amp;nbsp;11.1.3,&amp;nbsp;10.2.10,&amp;nbsp;10.2.11,&amp;nbsp;11.1.5,&amp;nbsp;10.2.4-h19,&amp;nbsp;12.1.0,&amp;nbsp;10.2.9-h9"&amp;nbsp; (List I got from TAC, that said they didn't indicate an 11.0.X version which seems weird.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a work around for this, which is to restart both firewalls (obviously very intrusive) or running this command&amp;nbsp;&lt;SPAN&gt;"debug software restart process log-receiver."&amp;nbsp; I'm not certain of the impact of that restart command, so I would advise reaching out to TAC to confirm if you're hitting this bug or run the command in a maintenance window.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 15:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/594160#M118244</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-08-06T15:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic log source user different from User-ID log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/594212#M118255</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp; appreciate you sharing information. &lt;BR /&gt;For your issue, is the user that is wrongly mapped both an AD user?&lt;BR /&gt;Since in my case, it is a local firewall user. &lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 07:08:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/594212#M118255</guid>
      <dc:creator>EdmarFrancis</dc:creator>
      <dc:date>2024-08-07T07:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic log source user different from User-ID log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/594228#M118261</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/315823"&gt;@EdmarFrancis&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp; appreciate you sharing information. &lt;BR /&gt;For your issue, is the user that is wrongly mapped both an AD user?&lt;BR /&gt;Since in my case, it is a local firewall user.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;It was an AD mapped user (Both were AD mapped.)&amp;nbsp; I'm honestly not sure if this bug could be matched to local user account.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 12:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-source-user-different-from-user-id-log/m-p/594228#M118261</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-08-07T12:57:30Z</dc:date>
    </item>
  </channel>
</rss>

