<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source user not shown in some logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40202#M29488</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tied it without success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is strange, why I get user ip-mapping throught CLI but it is only shown in some traffic logs. :smileyconfused:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Oct 2012 14:23:52 GMT</pubDate>
    <dc:creator>david_rivas1</dc:creator>
    <dc:date>2012-10-23T14:23:52Z</dc:date>
    <item>
      <title>Source user not shown in some logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40200#M29486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have developed a script that collects user-ip mapping from a wireless controller and send this info to User-ID Agent. All these looks fine because I can see the users in the User-ID Agent monitor table, but when I look traffic logs on Palo Alto I can see some logs do not have a user identification and other logs have it, for the same source IP. I attach a screenshot where you can see what I am trying to explain :smileysilly:.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user-ip mapping is correctly catched by PaloAlto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;admin@PA-500&amp;gt; show user ip-user-mapping ip 172.21.8.195&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;IP address:&amp;nbsp; 172.21.8.195&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alumnes\zwillis&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Ident. By:&amp;nbsp;&amp;nbsp; AD&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Idle Timeout: 3581s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 3581s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Groups that the user belongs to (used in policy)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone knows what could be happening?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 08:05:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40200#M29486</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-10-22T08:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not shown in some logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40201#M29487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried increasing the user Identification time out on the User ID agent. The main issue here is the Agent not the PAN. Try increasing the time out to 120 minutes and dis able the netbios probing and only enabling the WMI probing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Hasnain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 16:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40201#M29487</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2012-10-22T16:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not shown in some logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40202#M29488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tied it without success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is strange, why I get user ip-mapping throught CLI but it is only shown in some traffic logs. :smileyconfused:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 14:23:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40202#M29488</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-10-23T14:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not shown in some logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40203#M29489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;During the time that the source user does not show in the traffic logs, are the users running a program that may require elevated privileges to Admin? If so, if you have the Admin user in the ignore list, for that one session of traffic when the user is running an application as an Admin, the username may not show.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 15:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40203#M29489</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2012-10-24T15:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not shown in some logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40204#M29490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The machines of these users are not in domain. That is the reason I used a script (obtain mapping from wireless controller) to send this mapping to the User-ID-Agent. Maybe these users use local admin account for some applications, but I have not configured admin ignoration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 15:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40204#M29490</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-10-24T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not shown in some logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40205#M29491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please add another snap shot of the traffic log that shows the either screen.. need to see if you are hitting the same rules for the users that are not be identified.&lt;/P&gt;&lt;P&gt;Also click on the detail icon.. Far left the one with the box and magnifying glass and add that snap shot too. &lt;/P&gt;&lt;P&gt;If you have time as well maybe calling into support will help so we can look at it closer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;Al&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 14:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-shown-in-some-logs/m-p/40205#M29491</guid>
      <dc:creator>acamacho</dc:creator>
      <dc:date>2012-10-25T14:56:48Z</dc:date>
    </item>
  </channel>
</rss>

