<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No User ID in traffic logs (unless I filter soruce user afterwards) and User activity report bla in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78547#M42971</link>
    <description>&lt;P&gt;Yes, tried all the above. Whats equally strange is the all looks fine via CLI. I get group mapping and everything but as soon as a show session all filter source-user it shows no actie sesssions and even looking at logs it shows source user ip as the firewall itself&amp;nbsp; user name is the WMI setup user name but no individual users at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@cobmqic3bpafw01(active)&amp;gt; show user server-monitor statistics&lt;/P&gt;
&lt;P&gt;Directory Servers: &lt;BR /&gt;Name TYPE Host Vsys Status &lt;BR /&gt;----------------------------------------------------------------------------- &lt;BR /&gt;qcdc01.org AD&amp;nbsp; vsys1 Connected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dmin@cobmqic3bpafw01(active)&amp;gt; show user ip-user-mapping all&lt;/P&gt;
&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;BR /&gt;10.20x.x.5 vsys1 AD qic\ser_qicb_vdidesktop 2688 2688 &lt;BR /&gt;10.xx.4.13 vsys1 AD qic\ser_qica2_vco 631 631 &lt;BR /&gt;10.204.9.x vsys1 AD qic\ser_qicb_visql 1884 1884&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2016 23:47:46 GMT</pubDate>
    <dc:creator>clyde.franklin</dc:creator>
    <dc:date>2016-05-23T23:47:46Z</dc:date>
    <item>
      <title>No User ID in traffic logs (unless I filter soruce user afterwards) and User activity report blank</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78335#M42909</link>
      <description>&lt;P&gt;Has any one&amp;nbsp; expereinced any issue to where the ACC shows source user-id but when ser report is ran its blank? Equallu I do not se user name in Traffic logs but&amp;nbsp; when I filter by source user the name shows up. I tried restarting agent and everything still no luck. I also can see user name in User ID agent on windows machine&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 19:39:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78335#M42909</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-18T19:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: No User ID in traffic logs (unless I filter soruce user afterwards) and User activity report bla</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78506#M42961</link>
      <description>&lt;P&gt;Hi...By default, the traffic log is showing only the last X number of lines of recent logs and maybe those logs do not have a source user? &amp;nbsp;If you scroll to the next page(s), &amp;nbsp;do you see the source users? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To verify if the PA has userID information, you can issue this CLI command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@pa200&amp;gt; show user ip-user-mapping all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This userID information is applied to all traffic and is used to record logs. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 14:08:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78506#M42961</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-05-23T14:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: No User ID in traffic logs (unless I filter soruce user afterwards) and User activity report bla</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78547#M42971</link>
      <description>&lt;P&gt;Yes, tried all the above. Whats equally strange is the all looks fine via CLI. I get group mapping and everything but as soon as a show session all filter source-user it shows no actie sesssions and even looking at logs it shows source user ip as the firewall itself&amp;nbsp; user name is the WMI setup user name but no individual users at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@cobmqic3bpafw01(active)&amp;gt; show user server-monitor statistics&lt;/P&gt;
&lt;P&gt;Directory Servers: &lt;BR /&gt;Name TYPE Host Vsys Status &lt;BR /&gt;----------------------------------------------------------------------------- &lt;BR /&gt;qcdc01.org AD&amp;nbsp; vsys1 Connected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dmin@cobmqic3bpafw01(active)&amp;gt; show user ip-user-mapping all&lt;/P&gt;
&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;BR /&gt;10.20x.x.5 vsys1 AD qic\ser_qicb_vdidesktop 2688 2688 &lt;BR /&gt;10.xx.4.13 vsys1 AD qic\ser_qica2_vco 631 631 &lt;BR /&gt;10.204.9.x vsys1 AD qic\ser_qicb_visql 1884 1884&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 23:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78547#M42971</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-23T23:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: No User ID in traffic logs (unless I filter soruce user afterwards) -CLOSING LOOP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78830#M43044</link>
      <description>&lt;P&gt;Wanted to close loop on this. When setting up UIA whether using the agent or agentless&amp;nbsp; one think that need to be look at is betweem domains if communication needed then from a server perspective it needs to be confirmed that there is a trust relationship built between the domains. Whether it be 1 way trust or bidirection. If the this not done then user-ids will never show up in traffic logs. This equally will create issue of user activity reports being blank. I workef with my server team to build this repaltionship and it worked like a charm and all UID's are flowing now.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 16:30:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-user-id-in-traffic-logs-unless-i-filter-soruce-user/m-p/78830#M43044</guid>
      <dc:creator>clyde.franklin</dc:creator>
      <dc:date>2016-05-31T16:30:14Z</dc:date>
    </item>
  </channel>
</rss>

