<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No result from &amp;quot;show user pan-agent user-IDs&amp;quot; command in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4239#M3126</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; It's ok after I open PAN agent console and click get group as you guide me. Other question is I must open PAN agent console and click get group after I add new user into AD? It isn't make sense to do this thing. I must always open PAN agent console?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you&lt;/P&gt;&lt;P&gt;TU&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Sep 2011 16:17:39 GMT</pubDate>
    <dc:creator>systemadmin_tu</dc:creator>
    <dc:date>2011-09-20T16:17:39Z</dc:date>
    <item>
      <title>No result from "show user pan-agent user-IDs" command</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4237#M3124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I just install pan-agent on my AD, windwos 2003 server, and configure PAN box to connect to this pan-agent. I can see traffic with user from AD server. I found result from command " show user ip-user-mapping all".&amp;nbsp; I can list group of AD with command " debug device-server dump user-group name". &lt;/P&gt;&lt;P&gt;&amp;nbsp; However after I run command "show user pan-agent user-IDs", it didn't return result. I found some misstake. I cann't control application usage with group name from AD on security policy. Moreover, after I add user on AD, PAN box didn't update list of new user from AD. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you,&lt;/P&gt;&lt;P&gt;TU&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 13:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4237#M3124</guid>
      <dc:creator>systemadmin_tu</dc:creator>
      <dc:date>2011-09-19T13:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: No result from "show user pan-agent user-IDs" command</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4238#M3125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to click&amp;nbsp; Get all from the first page of the PAN agent console? Can you see any user to IP mapping there? How many domain controllers do you have? Have you put all the domain controllers on the list which is mandatory? Are you running the agent with privilege to read AD security log?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 14:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4238#M3125</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-19T14:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: No result from "show user pan-agent user-IDs" command</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4239#M3126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; It's ok after I open PAN agent console and click get group as you guide me. Other question is I must open PAN agent console and click get group after I add new user into AD? It isn't make sense to do this thing. I must always open PAN agent console?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you&lt;/P&gt;&lt;P&gt;TU&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Sep 2011 16:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4239#M3126</guid>
      <dc:creator>systemadmin_tu</dc:creator>
      <dc:date>2011-09-20T16:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: No result from "show user pan-agent user-IDs" command</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4240#M3127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need to do so. Have you tried to add a new user and use that account to logon any one of the PCs? PA needs to see the user in AD log in order to have user to IP mapping. Also, if that user logon through a DC which is not added to the PAN agent, we won't see the log as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 04:05:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-result-from-quot-show-user-pan-agent-user-ids-quot-command/m-p/4240#M3127</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-21T04:05:22Z</dc:date>
    </item>
  </channel>
</rss>

