<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Event Generation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-event-generation/m-p/46791#M34395</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a question about the events used to map users to IP's in the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to documentation, the PA uses three event ID's to map users to IPs: 4768, 4769, 4770.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question I have is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a user (say his username is bsmith) is an IT administrator, and also has a username of bsmithadmin with administrative rights (he may use this account to map to admin shares, etc...).&amp;nbsp; If the user uses his admin account from his workstation to map shares or authenticate with servers, won't it generate an event ID 4769?&amp;nbsp; In doing research, I found documentation that says a 4769 is generated when users access servers or resources on the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouldn't that cause the PA to map the admin account to the workstation IP instead of his regular user account, thus messing with the policies applied to him?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to change which events trigger an update in the PA, and say only read event id 4768's that indicate a successful login?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Nov 2011 16:51:47 GMT</pubDate>
    <dc:creator>bbrassart</dc:creator>
    <dc:date>2011-11-07T16:51:47Z</dc:date>
    <item>
      <title>User-ID Event Generation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-event-generation/m-p/46791#M34395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a question about the events used to map users to IP's in the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to documentation, the PA uses three event ID's to map users to IPs: 4768, 4769, 4770.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question I have is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a user (say his username is bsmith) is an IT administrator, and also has a username of bsmithadmin with administrative rights (he may use this account to map to admin shares, etc...).&amp;nbsp; If the user uses his admin account from his workstation to map shares or authenticate with servers, won't it generate an event ID 4769?&amp;nbsp; In doing research, I found documentation that says a 4769 is generated when users access servers or resources on the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouldn't that cause the PA to map the admin account to the workstation IP instead of his regular user account, thus messing with the policies applied to him?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to change which events trigger an update in the PA, and say only read event id 4768's that indicate a successful login?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 16:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-event-generation/m-p/46791#M34395</guid>
      <dc:creator>bbrassart</dc:creator>
      <dc:date>2011-11-07T16:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Event Generation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-event-generation/m-p/46792#M34396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@bbrassart:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your understanding of the situation is valid. The Pan Agent will pick up the username for the admin user when the fileshares are mapped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the present time the user identification agents do not support exclusion of event IDs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to see this feature implemented please get in touch with your sales team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another option would be to set up an ignore-user list that includes the bsmithadmin user. This will keep the Pan Agent from mapping any event IDs associated with bsmithadmin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 23:23:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-event-generation/m-p/46792#M34396</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-07T23:23:26Z</dc:date>
    </item>
  </channel>
</rss>

