<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring - source user not shown in log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6536#M4773</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem with PAN OS 4.1.6 and UI agent 4.1.6-5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jan 2013 14:40:56 GMT</pubDate>
    <dc:creator>systemadmin_tu</dc:creator>
    <dc:date>2013-01-08T14:40:56Z</dc:date>
    <item>
      <title>Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6530#M4767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Although the "agentID client" is installed on one of our domain controller boxes, I find that when using MONITOR log to look at the traffic, it doesn't show the "source user" of whom is currently logged in via Active Directory. Any idea why?&lt;/P&gt;&lt;P&gt;In addition, the monitor log will show the ip address and it will "resolve hostname" when checking the box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2012 16:39:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6530#M4767</guid>
      <dc:creator>robert_smith</dc:creator>
      <dc:date>2012-04-02T16:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6531#M4768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has this ever worked before, or is this a new installation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what version of the user-id agent and PAN OS Software are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A few things you can do is check to see if the firewall has any correct mappings by running:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are showing as unknown, then you need to open the agent installed on your DC and look to see if it's getting the correct mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason Seals&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2012 18:03:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6531#M4768</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-04-02T18:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6532#M4769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran the command you mentioned and it shows some the following result. I've omitted users domain/user name for privacy concerns.&lt;/P&gt;&lt;P&gt;The vpn 192.168.7.x are vpn globalprotect clients and they do show in the listing. So it seems it only is showing vpn clients at the moment. Does the user-id client agent need to be installed directly on the domain controller as we have it installed on our manage server which is a member server which runs on VMware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running PAN OS Software 4.1.2&lt;/P&gt;&lt;P&gt;The user-id client is running version 4.1.2-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-500&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ident. By User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle Timeout (s) Max. Timeout (s)&lt;BR /&gt;--------------- --------- -------------------------------- ---------------- ----------------&lt;BR /&gt;192.168.7.xxx&amp;nbsp; GP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (ommitted domain/user)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2468098&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2468098&lt;BR /&gt;192.168.x.xx&amp;nbsp;&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;BR /&gt;192.168.x.x&amp;nbsp;&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;BR /&gt;192.168.x.x&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;192.168.7.xxx&amp;nbsp;&amp;nbsp; GP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (ommitted domain/user)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2155146&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2155146&lt;BR /&gt;192.168.x.x&amp;nbsp;&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;192.168.x.x&amp;nbsp;&amp;nbsp;&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;BR /&gt;192.168.x.xx&amp;nbsp;&amp;nbsp;&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;192.168.x.xxx&amp;nbsp;&amp;nbsp; Unknown&amp;nbsp;&amp;nbsp; unknown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;Total: 9 users&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2012 19:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6532#M4769</guid>
      <dc:creator>robert_smith</dc:creator>
      <dc:date>2012-04-02T19:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6533#M4770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have User ID enabled on the zone from where your internal users are coming in?&lt;/P&gt;&lt;P&gt;Also, do the users authenticate against a DC that is not being monitored by the User ID agent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would appear that your users on the GP zone are showing up correctly as that zone has user ID enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you go to Network&amp;gt;&amp;gt;Zones&amp;gt;&amp;gt; check to see if the users are coming in on a zone that has UserID enabled (box is checked)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 18:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6533#M4770</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2012-04-05T18:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6534#M4771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The agent does not need to be installed directly on the DC. Just a machine that can read the DC's security logs. However, installing it directly on the DC can rule out some communication issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Saba said, it could be your zone not having userID checked. Since the firewall doesn't show the mappings, take a look at the agent and see if it's getting any mappings and is just having issues sending them to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Jason Seals &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2012 06:47:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6534#M4771</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-04-06T06:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6535#M4772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are seeing a similar issue on 3.1.2 client connecting to PANOS 4.0.11 (yes we do have an open case)&lt;/P&gt;&lt;P&gt;We've tried reinstalling the agent with out success&lt;/P&gt;&lt;P&gt;We've tried uninstalling the agent, doing a clean up and installing again.&lt;/P&gt;&lt;P&gt;No luck as yet, but we will update when we find a resolution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 12:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6535#M4772</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2012-06-06T12:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6536#M4773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem with PAN OS 4.1.6 and UI agent 4.1.6-5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 14:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6536#M4773</guid>
      <dc:creator>systemadmin_tu</dc:creator>
      <dc:date>2013-01-08T14:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring - source user not shown in log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6537#M4774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;same problem here with OS 4.1.9 and agent 4.1.4-3...intermittently empty source user field in traffic logs for the same source IP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 17:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/monitoring-source-user-not-shown-in-log/m-p/6537#M4774</guid>
      <dc:creator>kmurphy6</dc:creator>
      <dc:date>2013-01-22T17:41:38Z</dc:date>
    </item>
  </channel>
</rss>

