<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What difference are between 'user eq' and 'user in' in filter of traffic logs? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21387#M15600</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello HULK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I already looked above liked document. and I also tried to use "in SA" in the filter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But I could see nothing logs in traffic logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, PANOS is 5.0.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Aug 2014 05:20:47 GMT</pubDate>
    <dc:creator>KiCheon.Lee</dc:creator>
    <dc:date>2014-08-26T05:20:47Z</dc:date>
    <item>
      <title>What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21385#M15598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What difference are between 'user eq' and 'user in' in filter of traffic logs?&lt;/P&gt;&lt;P&gt;I want to see output which is filtered by partial user-ID not full user-ID.&lt;/P&gt;&lt;P&gt;For example, There are as below user-IDs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SA10001&lt;/P&gt;&lt;P&gt;SA10002&lt;/P&gt;&lt;P&gt;UQ20001&lt;/P&gt;&lt;P&gt;UQ20002&lt;/P&gt;&lt;P&gt;.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to filter for all started 'SA' users in traffic logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KC Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 03:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21385#M15598</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-08-26T03:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21386#M15599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello KC,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;eq&lt;/SPAN&gt;" will try to match the exact keyword. Could you please try to use "in SA" in the filter (partial match keyword). Please find mentioned KB article for available options: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6251"&gt;Filtering Traffic Logs for Only Unidentified Users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 04:36:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21386#M15599</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-26T04:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21387#M15600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello HULK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I already looked above liked document. and I also tried to use "in SA" in the filter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But I could see nothing logs in traffic logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, PANOS is 5.0.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 05:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21387#M15600</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-08-26T05:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21388#M15601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12.727272033691406px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hi cheon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12.727272033691406px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I also tried to do test and it's available but not working.&lt;/P&gt;&lt;P style="font-size: 12.727272033691406px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;GOOD LUCK~&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 11:48:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21388#M15601</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-08-26T11:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21389#M15602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/6808"&gt;cheon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"User eq" looks for a exact match that you provide. "User in" however can be used to perform queries such as:&lt;/P&gt;&lt;P&gt;user.src in "cn=test,ou=sec_g,ou=pan,dc=paloaltonetworks,dc=local"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="user_in.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15112_user_in.jpg" style="height: 167px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thus "User in" looks if the user is part of the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case if all username starting with SA are part of a particular group you can provide a similar query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it works out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 20:53:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21389#M15602</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-08-26T20:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21390#M15603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer, csharma.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we use xml method not AD with LDAP.&lt;/P&gt;&lt;P&gt;In case, How should I use filtering?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2014 02:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21390#M15603</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-08-28T02:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21391#M15604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/6808"&gt;cheon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do the same thing if you are using XML API, just provide the group entry as follows:&lt;/P&gt;&lt;P&gt;&amp;lt;uid-message&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;version&amp;gt;1.0&amp;lt;/version&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;type&amp;gt;update&amp;lt;/type&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;payload&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;login&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;entry name="plano2003\csharma" ip="192.168.39.209" timeout="20"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/login&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;groups&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;entry%20name="group1"&amp;gt; &lt;STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;plano2003/csharma is part of group1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;members&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;entry name="plano2003\csharma"/&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/members&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/entry&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/groups&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/payload&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/uid-message&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if you check the CLI:&lt;/P&gt;&lt;P&gt;[edit]&lt;/P&gt;&lt;P&gt;admin@39-PA-3020# run show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vsys&amp;nbsp;&amp;nbsp; From&amp;nbsp;&amp;nbsp;&amp;nbsp; User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IdleTimeout(s) MaxTimeout(s)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;/P&gt;&lt;P&gt;192.168.39.209&amp;nbsp; vsys1&amp;nbsp; XMLAPI&amp;nbsp; plano2003\csharma&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1194&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1194&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total: 1 user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@39-PA-3020# run show user group list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group1 &lt;STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;group we just added&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the query will be modified as follows (user.src in 'group1') where group1 is the group of the users we added through XML API.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="user_in_XML.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15191_user_in_XML.JPG" style="height: 92px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case you can modify your XML API to make all users starting with 'SA' as one group and users starting with as 'UQ' as part of another group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2014 03:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21391#M15604</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-08-28T03:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: What difference are between 'user eq' and 'user in' in filter of traffic logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21392#M15605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;Hi csharma,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;Thanks for your answer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;It help me very useful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;But my customer want to filter partial characters on many groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;Do you know another way excepted same group?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;We can not category group by partial characters.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 02:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-difference-are-between-user-eq-and-user-in-in-filter-of/m-p/21392#M15605</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2014-09-05T02:31:13Z</dc:date>
    </item>
  </channel>
</rss>

