<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent Windows 2003 logon events in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67401#M39514</link>
    <description>&lt;P&gt;I'm kind of confused...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your issue is that in your enviornment UIA isn't always providing user attribution for users logged into your domain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And you're saying that the CP process isn't fully identifying the remaining users that have not been idenfited?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2015 13:04:57 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2015-10-28T13:04:57Z</dc:date>
    <item>
      <title>User-ID Agent Windows 2003 logon events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67400#M39513</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I sometimes have a really hard life mapping domain users with old Windows 2003 forests using UID Agent (no matter if version 6 or 7))&lt;/P&gt;
&lt;P&gt;I'll try to explain: when and only when using UID Agent I cannot read &lt;EM&gt;all&lt;/EM&gt; users logon events or, worse, I can't read users at all, ending up having not all domain users transparently mapped and issues with captive portal showing up to not yet mapped users.&lt;/P&gt;
&lt;P&gt;It's been a while that I use a simple workaround, that is to say replacing the UID Agent with the old &lt;EM&gt;PANAgent&lt;/EM&gt;...&lt;/P&gt;
&lt;P&gt;I know this is absurd, but PANAgent can &lt;EM&gt;always&lt;/EM&gt; read &lt;EM&gt;all&lt;/EM&gt; users, the problem is that the doc states it's no more supported starting from PanOS 6.0 (though it appears to be still working with 7.0 too...). So far I'm convinced that this must not be related to the audit policies on the domain controllers.&lt;/P&gt;
&lt;P&gt;According to the docs these are the Windows event logs the UID tries to lookup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows 2000 - 2003&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SUCCESS_NET_LOGON = 540&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AUTH_TICKET_GRANTED = 672&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SERVICE_TICKET_GRANTED = 673&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TICKET_GRANTED_RENEW = 674&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACCOUNT_USED_FOR_LOGON = 680&lt;BR /&gt;&lt;BR /&gt;Windows 2008&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; LOGON_SUCCESS_W2008 = 4624&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AUTH_TICKET_GRANTED_W2008 = 4768&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SERVICE_TICKET_GRANTED = 4769&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TICKET_GRANTED_RENEW_W2008 = 4770&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACCOUNT_USED_FOR_LOGON_W2008 = 4776&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody having similar issues?&lt;/P&gt;
&lt;P&gt;Of course I don't like keep on using PANAgent, but if it can map all users, UID must be able too.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 12:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67400#M39513</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2015-10-28T12:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Windows 2003 logon events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67401#M39514</link>
      <description>&lt;P&gt;I'm kind of confused...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your issue is that in your enviornment UIA isn't always providing user attribution for users logged into your domain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And you're saying that the CP process isn't fully identifying the remaining users that have not been idenfited?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 13:04:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67401#M39514</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-10-28T13:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Windows 2003 logon events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67403#M39516</link>
      <description>&lt;P&gt;Do you have only "Read Security Log" checked or "Read Session" aswell under user identification?&lt;/P&gt;
&lt;P&gt;First contains only logon events, other access to file servers and network printing aswell.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 13:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67403#M39516</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-28T13:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Windows 2003 logon events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67420#M39519</link>
      <description>&lt;P&gt;Yes UIA isn't always able to read windows logon events, while the old PANAgent is.&lt;/P&gt;
&lt;P&gt;Please note that I have sometimes this issue with very old windows domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the CP, when and if it's configured as a "complementary" id mechanism with respect to trasparent user-id by the UIA, it bothers users because trasparent id fails. Just to stay on topic, please forget about CP, I have problems with UIA AND with old domains only.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 22:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67420#M39519</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2015-10-28T22:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Windows 2003 logon events</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67421#M39520</link>
      <description>&lt;P&gt;And yes, of course I have the "Enable Security Log Monitor" option flagged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PANAgent in the very same W2003 domains and with the very same domain controllers always reads all logon events...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it's about since I've started working with PaloAlto (3 years ago) that I sometimes experience this strange behaviour and really can't understand why I have to rollback to PANagent.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 22:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-windows-2003-logon-events/m-p/67421#M39520</guid>
      <dc:creator>errevisystem</dc:creator>
      <dc:date>2015-10-28T22:28:59Z</dc:date>
    </item>
  </channel>
</rss>

