<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reports based on groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4087#M3026</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we already tried both but report comes empty.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Jul 2013 12:02:05 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-07-09T12:02:05Z</dc:date>
    <item>
      <title>Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4085#M3024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we try to get custom reports by typing a query for source user(domain\group) and run now, it gets empty.when we type user name it is working.&lt;/P&gt;&lt;P&gt;Any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 07:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4085#M3024</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-09T07:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4086#M3025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Try following query : &lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-family: 'courier new', courier;"&gt;(user.src in 'cn=home,cn=users,dc=amb,dc=local') &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-family: 'courier new', courier;"&gt;OR (user.src in 'amb\home')&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 09:15:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4086#M3025</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-09T09:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4087#M3026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we already tried both but report comes empty.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 12:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4087#M3026</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-09T12:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4088#M3027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you query traffic logs&amp;nbsp; using query in above formats?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 18:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4088#M3027</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-09T18:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4089#M3028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for users yes we can query with domain\user&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 20:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4089#M3028</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-09T20:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4090#M3029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log format in 3.x is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain, receive_time, serial, type, subtype, config_ver, time_generated, src, dst, natsrc, natdst, rule, srcuser, dstuser, app, vsys, from, to, inbound_if, outbound_if, logset, time_received,&lt;/P&gt;&lt;P&gt;sessionid, repeatcnt, sport, dport, natsport, natdport, flags, proto, action, bytes, bytes_sent, bytes_received, packets, start, elapsed, category, padding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the record of the group is not written to the traffic log, i suppose it is an expected behavior that the queries based on groups will return empty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may be wrong since its 3.x panos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deepak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 22:10:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4090#M3029</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-07-09T22:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4091#M3030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping ip &amp;lt;ip of the user which shows up in traffic Logs&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the Group in the Group(s) field for the query in the traffic logs&amp;nbsp; :&amp;nbsp; (user.src in '&lt;STRONG&gt;Group in the Group(s) field&lt;/STRONG&gt;')&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 23:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4091#M3030</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-09T23:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4092#M3031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.We did that.&lt;/P&gt;&lt;P&gt;Still reports come empty for gorups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jul 2013 00:03:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4092#M3031</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-10T00:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Reports based on groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4093#M3032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is PAN firewall retrieving the user-group information properly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;show user group name &amp;lt;group name&amp;gt;&amp;nbsp; //this should list all the group members of the group&lt;/P&gt;&lt;P&gt;&amp;gt;show user user-IDs match user &amp;lt;username&amp;gt; //shows the groups a user is a part of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall is able to identify the users in the group and see traffic logs for these users, it should match the query for the report.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jul 2013 03:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reports-based-on-groups/m-p/4093#M3032</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-07-10T03:23:50Z</dc:date>
    </item>
  </channel>
</rss>

