<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless User-ID not reading Security Log on AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98378#M44134</link>
    <description>&lt;P&gt;did you make sure succesful logon auditing is enabled on the Active Directory? by default this is turned off so there aren't any logs to read:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-07-19_10-43-02.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2016-07-19_10-43-02.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jul 2016 08:46:02 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-07-19T08:46:02Z</dc:date>
    <item>
      <title>Agentless User-ID not reading Security Log on AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98343#M44131</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I'm&amp;nbsp;pretty new to PA so there may be something obvious that I have missed.&lt;BR /&gt;&lt;BR /&gt;The issue I am having is trying to get the Agentless&amp;nbsp;User-ID connecting and reading Security Logs from AD.&amp;nbsp;All the users are coming up as Unknown:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show user ip-user-mapping all

 

IP              Vsys   From    User                             IdleTimeout(s) MaxTimeout(s)
 --------------- ------ ------- -------------------------------- -------------- -------------
 10.10.10.43     vsys1  Unknown unknown                          1              4
 10.10.9.16      vsys1  Unknown unknown                          2              5
 10.10.12.40     vsys1  Unknown unknown                          1              4
 10.10.0.17      vsys1  Unknown unknown                          2              5
 10.10.4.181     vsys1  Unknown unknown                          1              4&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The environment is PAN 3020 7.0.8, AD on Server 2808 R2. PAN is running as a very simple Virtual Wire.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have&amp;nbsp;created the WMI Authentication user&amp;nbsp;with the correct rights to AD (Distributed, COM, Event Log Readers, Server Operators) also added CIMV2 Enable Account and Remote Enable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show user server-monitor statistics

 

Directory Servers:
Name                           TYPE     Host            Vsys    Status
 -----------------------------------------------------------------------------
 ad1.domain.name               AD      192.168.1.1     vsys1    Connected
 ad1.domain.name               AD      192.168.1.2     vsys1    Connected


Syslog Servers:
 Name                      Connection Host            Vsys    Status
 -----------------------------------------------------------------------------&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;One of the things that concerns me is that the number of logs read is 0:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show user server-monitor state all

 

        UDP Syslog Listener Service is disabled
        SSL Syslog Listener Service is disabled

Server: ad1.domain.name(vsys: vsys1) (job 1449)
        Host: 192.168.1.1
        num of log query made       : 462
        num of log query failed     : 0
        num of log read             : 0
        last record timestamp       : 0
        last record time            :

Server: ad2.domain.name(vsys: vsys1)
        Host: 192.168.1.2
        num of log query made       : 389
        num of log query failed     : 0
        num of log read             : 0
        last record timestamp       : 0
        last record time            :


         num of log read            : 0
         last record timestamp      : 0
         last record time           :&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;show user group list&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;STRONG&gt;&lt;SPAN&gt;show user group name&amp;nbsp;&amp;lt;group&amp;gt;&lt;/SPAN&gt;&lt;/STRONG&gt; both give expected results from AD. If I check 'Enable Session' from within the User ID Agent setup I see some users but not all. I have run as the WMI Authentication as a Domain Admin with the same results. I have checked the domain controllers and both have multiple 4624, 4768, 4769 events&amp;nbsp;in the last hour but no 4770.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can any one point me in another direction of things to test?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 01:42:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98343#M44131</guid>
      <dc:creator>stuart.l</dc:creator>
      <dc:date>2016-07-19T01:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not reading Security Log on AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98378#M44134</link>
      <description>&lt;P&gt;did you make sure succesful logon auditing is enabled on the Active Directory? by default this is turned off so there aren't any logs to read:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2016-07-19_10-43-02.jpg"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/B81F31A7B44084F326ABA63EFCA50C9D/responsive_peak/images/image_not_found.png" alt="2016-07-19_10-43-02.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 08:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98378#M44134</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-07-19T08:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not reading Security Log on AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98488#M44139</link>
      <description>&lt;P&gt;Thanks for the reply reaper. Yes I have both the 'Audit account logon events' and 'Audit logon events' logging success. I have verified these in the logs; 4624 is a 'logon event' and 4768 is an 'account logon'. I confirmed these events by running event viewer remotely using the account set for WMI Authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also now updated the unit to 7.1.3 but still can't find the cause of the logs not being read.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 23:26:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98488#M44139</guid>
      <dc:creator>stuart.l</dc:creator>
      <dc:date>2016-07-19T23:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not reading Security Log on AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98503#M44143</link>
      <description>&lt;P&gt;Fixed....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The system&amp;nbsp;date was incorrect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll shut the door on the way out.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 00:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/98503#M44143</guid>
      <dc:creator>stuart.l</dc:creator>
      <dc:date>2016-07-20T00:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not reading Security Log on AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/490821#M104921</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I was also facing the same issue, it was using the public DNS and when I change to the internal DNS to AD.&lt;/P&gt;&lt;P&gt;Start working fine.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 17:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/490821#M104921</guid>
      <dc:creator>MohammedShanawazuddin</dc:creator>
      <dc:date>2022-05-24T17:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID not reading Security Log on AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/491271#M104942</link>
      <description>&lt;P&gt;Hi, we are facing same issue on AD:2019 and PAN OS 10.1.5h1, we check it already time sync all system but it still not get user-id mapping. We still get unknown. Could you pls explain more about your solutions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 06:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-not-reading-security-log-on-ad/m-p/491271#M104942</guid>
      <dc:creator>Yoekleng</dc:creator>
      <dc:date>2022-05-25T06:21:22Z</dc:date>
    </item>
  </channel>
</rss>

