<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent Errors on Domain Controllers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35009#M25700</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dannon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DCOM errors are most probably due to WMI probing for IPs that are not responding. Can you please disable WMI probing under user-ID setup and test to see if the system error messages stopped ?&lt;/P&gt;&lt;P&gt;On PAN User-ID agent, go to setup --&amp;gt; click edit --&amp;gt; client probing --&amp;gt; uncheck WMI probing checkbox&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Helpful doc:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2867"&gt;User-ID Agent Generating DCOM and Kerberos System Errors&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Dec 2014 18:19:30 GMT</pubDate>
    <dc:creator>Mystique</dc:creator>
    <dc:date>2014-12-03T18:19:30Z</dc:date>
    <item>
      <title>User-ID Agent Errors on Domain Controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35008#M25699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm getting the following error showing up in event viewer on our Windows domain controller.&amp;nbsp; We have 4 DC total that have the the user-id agent installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="dcom_error.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17125_dcom_error.PNG" style="height: 679px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see, I am getting a lot of these error.&amp;nbsp; The IP in question is one from our BYOD subnet, meaning it could be a end-user personal device.&amp;nbsp; Most of the IPs in the error logs are from this subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also seeing the following on the User-Agent logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="user-agent_error.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17126_user-agent_error.PNG" style="height: 457px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if they are related or not.&amp;nbsp; When I setup the agent, I left all settings at their defaults, except for adding our service account for start-up and adding the other DCs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 18:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35008#M25699</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2014-12-03T18:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Errors on Domain Controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35009#M25700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dannon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DCOM errors are most probably due to WMI probing for IPs that are not responding. Can you please disable WMI probing under user-ID setup and test to see if the system error messages stopped ?&lt;/P&gt;&lt;P&gt;On PAN User-ID agent, go to setup --&amp;gt; click edit --&amp;gt; client probing --&amp;gt; uncheck WMI probing checkbox&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Helpful doc:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2867"&gt;User-ID Agent Generating DCOM and Kerberos System Errors&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 18:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35009#M25700</guid>
      <dc:creator>Mystique</dc:creator>
      <dc:date>2014-12-03T18:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Errors on Domain Controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35010#M25701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, turning off WMI caused the errors to cease.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem now is that I want to have WMI enabled, but my server admin doesn't want all the logs flooded with these entries on the DCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What to do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2015 16:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35010#M25701</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2015-02-19T16:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Errors on Domain Controllers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35011#M25702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've found that we have better results with user-id to ip mapping with having WMI probing enabled.&amp;nbsp; I turned it on, and told our server admin to calm down.&amp;nbsp; &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&amp;nbsp; It's still messy looking and I would like to have Palo put this in a separate application log in event viewer.&amp;nbsp; I've seen other filtering software do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2015 14:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-errors-on-domain-controllers/m-p/35011#M25702</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2015-03-11T14:29:49Z</dc:date>
    </item>
  </channel>
</rss>

