<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30349#M22197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That sounds like an enhancement request for your local SE as here's what the agent is intended to do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Pan-agent is a Windows application/service doing the following tasks:&lt;/P&gt;&lt;UL style="margin-top:0in" type="disc"&gt;&lt;LI class="MsoNormal" style="mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;Get&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Groups/Users from the configured domain controller and send to Pan Device&lt;/LI&gt;&lt;LI class="MsoNormal" style="mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;Get&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the IP-Username mapping for the configured domain and send to Pan Device &lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level1 lfo2; tab-stops:list .75in"&gt;&lt;SPAN style="mso-bidi-font-family: Wingdings; mso-list: Ignore; font-family: Wingdings; mso-fareast-font-family: Wingdings; "&gt;Ø&lt;SPAN style="font:7.0pt &amp;amp;quot;Times New Roman&amp;amp;quot;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Read security logs from the configured domain controllers to analyze the domain user logon event&lt;/P&gt;&lt;P class="MsoNormal" style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level1 lfo2; tab-stops:list .75in"&gt;&lt;SPAN style="mso-bidi-font-family: Wingdings; mso-list: Ignore; font-family: Wingdings; mso-fareast-font-family: Wingdings; "&gt;Ø&lt;SPAN style="font:7.0pt &amp;amp;quot;Times New Roman&amp;amp;quot;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;If enabled, probe the user IP detected from the security log reading to see if the user is sill logged on that IP&lt;/P&gt;&lt;P class="MsoNormal" style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level1 lfo2; tab-stops:list .75in"&gt;&lt;SPAN style="mso-bidi-font-family: Wingdings; mso-list: Ignore; font-family: Wingdings; mso-fareast-font-family: Wingdings; "&gt;Ø&lt;SPAN style="font:7.0pt &amp;amp;quot;Times New Roman&amp;amp;quot;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Enumerate the net sessions from the configured domain controllers to get the IP-Username mappings for the net session&lt;/P&gt;&lt;UL style="margin-top:0in" type="disc"&gt;&lt;LI class="MsoNormal" style="mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;Forward&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the NTLM message received from Pan Device to the domain controllers and&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vice versa to support NTLM authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Feb 2011 18:05:28 GMT</pubDate>
    <dc:creator>gswcowboy</dc:creator>
    <dc:date>2011-02-11T18:05:28Z</dc:date>
    <item>
      <title>User-ID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30348#M22196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to use the User-ID Agent to scan the logs from a machine configured as an Event Collector.&amp;nbsp; I have an event log called "Forwarded Events" which holds centralised logon/logoff events for another tool.&amp;nbsp; It would be good to leverage that information for Palo too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gary &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Feb 2011 17:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30348#M22196</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-02-11T17:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30349#M22197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That sounds like an enhancement request for your local SE as here's what the agent is intended to do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Pan-agent is a Windows application/service doing the following tasks:&lt;/P&gt;&lt;UL style="margin-top:0in" type="disc"&gt;&lt;LI class="MsoNormal" style="mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;Get&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Groups/Users from the configured domain controller and send to Pan Device&lt;/LI&gt;&lt;LI class="MsoNormal" style="mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;Get&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the IP-Username mapping for the configured domain and send to Pan Device &lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level1 lfo2; tab-stops:list .75in"&gt;&lt;SPAN style="mso-bidi-font-family: Wingdings; mso-list: Ignore; font-family: Wingdings; mso-fareast-font-family: Wingdings; "&gt;Ø&lt;SPAN style="font:7.0pt &amp;amp;quot;Times New Roman&amp;amp;quot;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Read security logs from the configured domain controllers to analyze the domain user logon event&lt;/P&gt;&lt;P class="MsoNormal" style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level1 lfo2; tab-stops:list .75in"&gt;&lt;SPAN style="mso-bidi-font-family: Wingdings; mso-list: Ignore; font-family: Wingdings; mso-fareast-font-family: Wingdings; "&gt;Ø&lt;SPAN style="font:7.0pt &amp;amp;quot;Times New Roman&amp;amp;quot;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;If enabled, probe the user IP detected from the security log reading to see if the user is sill logged on that IP&lt;/P&gt;&lt;P class="MsoNormal" style="margin-left:.75in;text-indent:-.25in;mso-list:l1 level1 lfo2; tab-stops:list .75in"&gt;&lt;SPAN style="mso-bidi-font-family: Wingdings; mso-list: Ignore; font-family: Wingdings; mso-fareast-font-family: Wingdings; "&gt;Ø&lt;SPAN style="font:7.0pt &amp;amp;quot;Times New Roman&amp;amp;quot;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Enumerate the net sessions from the configured domain controllers to get the IP-Username mappings for the net session&lt;/P&gt;&lt;UL style="margin-top:0in" type="disc"&gt;&lt;LI class="MsoNormal" style="mso-list:l0 level1 lfo1;tab-stops:list .5in"&gt;Forward&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the NTLM message received from Pan Device to the domain controllers and&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vice versa to support NTLM authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Feb 2011 18:05:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30349#M22197</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-02-11T18:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30350#M22198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may be able to script something and use our XML API into the user-ID agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Feb 2011 18:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30350#M22198</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-02-11T18:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30351#M22199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how would i do that, any help would be apperciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2012 01:14:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent/m-p/30351#M22199</guid>
      <dc:creator>kimalat</dc:creator>
      <dc:date>2012-04-26T01:14:13Z</dc:date>
    </item>
  </channel>
</rss>

