<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Agentless question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77597#M42647</link>
    <description>&lt;P&gt;Is there a reason why with Agentless User-ID I still never see any logs in Monitor? As shown below it definitaely is working but traffice logs do not sohw user-ids. I have a any any policy and user-id&amp;nbsp; box is checked on&amp;nbsp; the zones. ANy ideas? I ahve agent on a 2012 server I do see in logs ia se failed to connecr to LDAP but def its working from output&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dmin@PALO-TIA-03P vsys4(active-primary)&amp;gt; show user ip-user-mapping-mp all&lt;/P&gt;
&lt;P&gt;IP Vsys From User Timeout (sec) &lt;BR /&gt;--------------- ------ ------- -------------------------------- ----------------&lt;BR /&gt;10.64.21.84 vsys4 UIA ad\rivea 880&lt;BR /&gt;10.1.97.119 vsys4 UIA ad\miche 611&lt;BR /&gt;10.64.19.66 vsys4 UIA ad\mclaugm 1215&lt;BR /&gt;10.64.42.65 vsys4 UIA ad\treeced 265&lt;BR /&gt;10.64.42.104 vsys4 UIA ad\kopitsc 1045&lt;BR /&gt;10.148.2.216 vsys4 UIA ad\mumphre 652&lt;BR /&gt;10.84.2.50 vsys4 UIA ad\bursono 981&lt;BR /&gt;10.64.46.156 vsys4 UIA ad\xueli 977&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 May 2016 14:02:59 GMT</pubDate>
    <dc:creator>clyde.franklin</dc:creator>
    <dc:date>2016-05-06T14:02:59Z</dc:date>
    <item>
      <title>User-ID Agentless question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77597#M42647</link>
      <description>&lt;P&gt;Is there a reason why with Agentless User-ID I still never see any logs in Monitor? As shown below it definitaely is working but traffice logs do not sohw user-ids. I have a any any policy and user-id&amp;nbsp; box is checked on&amp;nbsp; the zones. ANy ideas? I ahve agent on a 2012 server I do see in logs ia se failed to connecr to LDAP but def its working from output&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dmin@PALO-TIA-03P vsys4(active-primary)&amp;gt; show user ip-user-mapping-mp all&lt;/P&gt;
&lt;P&gt;IP Vsys From User Timeout (sec) &lt;BR /&gt;--------------- ------ ------- -------------------------------- ----------------&lt;BR /&gt;10.64.21.84 vsys4 UIA ad\rivea 880&lt;BR /&gt;10.1.97.119 vsys4 UIA ad\miche 611&lt;BR /&gt;10.64.19.66 vsys4 UIA ad\mclaugm 1215&lt;BR /&gt;10.64.42.65 vsys4 UIA ad\treeced 265&lt;BR /&gt;10.64.42.104 vsys4 UIA ad\kopitsc 1045&lt;BR /&gt;10.148.2.216 vsys4 UIA ad\mumphre 652&lt;BR /&gt;10.84.2.50 vsys4 UIA ad\bursono 981&lt;BR /&gt;10.64.46.156 vsys4 UIA ad\xueli 977&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2016 14:02:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77597#M42647</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-06T14:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentless question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77656#M42665</link>
      <description>&lt;P&gt;Run the command "show session all filter source &amp;lt;ip&amp;gt;"&amp;nbsp; it will show session id now run the command "show session id &amp;lt;id&amp;gt;" now check if there is user name in the output or not. Might be you are not logging the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Filter the logs with the help of ip address and check if you have logs or not. Try removing the servers and do a commit and then add the server and do a commit and check if that helps or not.&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2016 12:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77656#M42665</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-05-07T12:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentless question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77687#M42675</link>
      <description>&lt;P&gt;Did you enable&amp;nbsp;User-ID on apropriate security zone(s)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 07:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77687#M42675</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-05-09T07:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentless question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77823#M42721</link>
      <description>&lt;P&gt;Ensure that the Monitor tab has the "Source User" column. Additionally I found that restarting the userID deamon helped me with a few problems:&lt;/P&gt;
&lt;P&gt;&amp;gt; debug software restart process user-id core yes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Restarting the management plane helped me as well (this will not affect normal traffic):&lt;/P&gt;
&lt;P&gt;&amp;gt; debug software restart process management-server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also follow the user-id log for more info.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; tail follow yes mp-log useridd.log&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 15:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77823#M42721</guid>
      <dc:creator>JDominguez</dc:creator>
      <dc:date>2016-05-10T15:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentless question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77837#M42726</link>
      <description>only use the "core yes" toggle if instructed to do so by TAC as this will create a core file&lt;BR /&gt;&lt;BR /&gt;the core file can be used by support if they need to investigate an issue with a process, but generating a core when not needed will take up unnecessary disk space&lt;BR /&gt;core files are not automatically pruned to conserve debug data in case a process were to crash, this also means if there have been enough unsolicited core files created, there may not be enough space if an actual core were to happen&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;you can clear out old core files with the command &amp;gt; delete core-file</description>
      <pubDate>Tue, 10 May 2016 17:40:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77837#M42726</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-10T17:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentl question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77990#M42779</link>
      <description>&lt;P&gt;Tried all these recommnedations and the User- Agent&amp;nbsp; Monitor&amp;nbsp; tab&amp;nbsp; still I show only2&amp;nbsp; IPs which is the IP of the firewall and the IP of my actual PC. I still never see any user that are showing logged under cli comning in on the agent. I have pretty much read evey article that esist on PA and User -ID set to no avail. So Im going presume that my issue is maybe log rellated on server itself. Apprently Im suppose to see below type responses from Agent logs which I never do.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;4768 (Authentication Ticket Granted)&lt;/LI&gt;
&lt;LI&gt;4769 (Service Ticket Granted)&lt;/LI&gt;
&lt;LI&gt;4770 (Ticket Granted Renewed)&lt;/LI&gt;
&lt;LI&gt;4624 (Logon Success)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 12 May 2016 13:15:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77990#M42779</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-12T13:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentl question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77994#M42782</link>
      <description>&lt;P&gt;Hi Clyde&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you open the Windows event viewer, do these event ID's ever show up?&lt;/P&gt;
&lt;P&gt;you may need to enable success auditing in the domain security settings:&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-05-12_15-18-15.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2016-05-12_15-18-15.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 13:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77994#M42782</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-05-12T13:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agentless question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77995#M42783</link>
      <description>&lt;P&gt;For screenshot below I do have the first option shows&amp;nbsp; as "Success" but the other options do not ubder Audit features. Do I need on some of the the other options as well like audit lohon events?&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 13:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agentless-question/m-p/77995#M42783</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-12T13:25:24Z</dc:date>
    </item>
  </channel>
</rss>

