<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID records timing out? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48305#M35549</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have an environment which has multiple USER-ID agents installed/configure and the agentless option via WMI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be an issue with user-id records timing out. After x amount of time, users start matching on a catch all policy at the end because there is no longer a username tied to their IP address. If they log off and back on, it starts working fine again until it times out after x number of minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something simple to resolving this that I am overlooking?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jun 2014 14:16:54 GMT</pubDate>
    <dc:creator>SDorsey</dc:creator>
    <dc:date>2014-06-20T14:16:54Z</dc:date>
    <item>
      <title>User-ID records timing out?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48305#M35549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have an environment which has multiple USER-ID agents installed/configure and the agentless option via WMI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be an issue with user-id records timing out. After x amount of time, users start matching on a catch all policy at the end because there is no longer a username tied to their IP address. If they log off and back on, it starts working fine again until it times out after x number of minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something simple to resolving this that I am overlooking?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 14:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48305#M35549</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-06-20T14:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID records timing out?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48306#M35550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could it be that the WMI probe doesn't work? If the WMI probe doesn't get a response it deletes the user mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the output from debug user-id dump probing-stats?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 14:37:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48306#M35550</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-06-20T14:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID records timing out?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48307#M35551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am guessing that is it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;num of initial probe made&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;: 115617&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;num of initial probe succeeded&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;: 3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;num of initial probe failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;: 115514&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;num of periodic probe made&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;: 14&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;num of periodic probe succeeded&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;: 1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;num of periodic probe failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&lt;P&gt;: 13&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I just need to find out why they are failing. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 15:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48307#M35551</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-06-20T15:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID records timing out?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48308#M35552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PCs that are being probed are likely not set for WMI responses.&lt;/P&gt;&lt;P&gt;As for why it works when the user logs in again, that is how IP to user mappings are made so that makes sense.&lt;/P&gt;&lt;P&gt;In addition to WMI probing, (considering these appear to be failing) you can be monitoring other servers in the Windows domain (e.g. file maps. printers, exchange mail servers) so that you can maintain the mapping and the user does not have to log in to refresh the mappings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to maintain mappings as the user maps drives etc. enable "server session read" on the UserID agent and the UserID agentless on the firewall so even if WMI probes you may have success in maintaining the user to ip mappings without relying solely on when the users log in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 15:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48308#M35552</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2014-06-20T15:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID records timing out?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48309#M35553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you still want to use WMI probing you should verify the user you use for the query. Here is a DOC how you can troubleshoot WMI problems:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1254"&gt;How to Troubleshoot WMI  &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 15:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-records-timing-out/m-p/48309#M35553</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-06-20T15:32:09Z</dc:date>
    </item>
  </channel>
</rss>

