<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermittent UserID - Syslog Parser - in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/595449#M118501</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185085"&gt;@NSutfin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Note that traffic logs are generated at the end of the session. Although the logs are generated few seconds apart, the actuall session for each log may have started minutes apart.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try the following:&lt;/P&gt;
&lt;P&gt;- Check the session start timestamp for two logs one with user-id and one without&lt;/P&gt;
&lt;P&gt;- Check the user-ID logs to see the timestamp when the user-to-ip mapping was created&lt;/P&gt;
&lt;P&gt;- Verify the mapping timeout has not expired for the two session start timestamps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2024 09:12:07 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2024-08-21T09:12:07Z</dc:date>
    <item>
      <title>Intermittent UserID - Syslog Parser -</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/595013#M118423</link>
      <description>&lt;P&gt;Anyone see this behavior? we are using syslog parser string for userid, no logout action, timeout set to 45 minutes ( default). You can see here that a flow within the same second shows a userid and then blank with same source address. FW running 10.2.7 h-8 . Any ideas?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NSutfin_0-1723726668467.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61539iD3004D0A83CE89BD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NSutfin_0-1723726668467.png" alt="NSutfin_0-1723726668467.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 13:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/595013#M118423</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2024-08-15T13:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent UserID - Syslog Parser -</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/595449#M118501</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185085"&gt;@NSutfin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Note that traffic logs are generated at the end of the session. Although the logs are generated few seconds apart, the actuall session for each log may have started minutes apart.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try the following:&lt;/P&gt;
&lt;P&gt;- Check the session start timestamp for two logs one with user-id and one without&lt;/P&gt;
&lt;P&gt;- Check the user-ID logs to see the timestamp when the user-to-ip mapping was created&lt;/P&gt;
&lt;P&gt;- Verify the mapping timeout has not expired for the two session start timestamps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 09:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/595449#M118501</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-08-21T09:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent UserID - Syslog Parser -</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/598131#M118979</link>
      <description>&lt;P&gt;What this actually was (cut out of screenshot), was that the loss of user-id was between different device-groups within a network. As a user was moving through the network encountering several different firewalls, not all firewalls had been set up for user-id. The search that was being used was against the whole group of firewalls using the user ip address.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 15:31:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intermittent-userid-syslog-parser/m-p/598131#M118979</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2024-09-18T15:31:18Z</dc:date>
    </item>
  </channel>
</rss>

