<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174239#M54763</link>
    <description>&lt;P&gt;So, obviously those group include lists are working for you then.(?) &amp;nbsp;You received the threshold alert both before and after setting up the include list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have anything on our PA-200 that uses groups so I haven't tested whether or not things work. It seems the list of all groups exists on the firewall so I don't see how the threshold means anything regardless of list settings unless it can't see the members of those groups. I didn't go that far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll dig into local logs just to make sure the others aren't logging and not alerting on that message.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2017 19:28:45 GMT</pubDate>
    <dc:creator>bspilde</dc:creator>
    <dc:date>2017-08-31T19:28:45Z</dc:date>
    <item>
      <title>SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174224#M54759</link>
      <description>&lt;P&gt;According to the&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/user-id-features/user-group-capacity-increase" target="_blank"&gt;New Features Guide&lt;/A&gt; in 7.1 PAN-OS the User Group Capacity was increased to a max of 3,200 groups IF you are following their note below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG border="0" /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Do not add entries to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Group Include List&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Custom Group&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;list—doing so limits the number of groups that policy rules can reference. Populated lists can have a combined maximum of only 640 groups but, by default, leaving the lists empty enables policy rules to reference up to a maximum of 3,200 groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have gone into these settings and removed all Custom Group lists and didn't have any Group Include List created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Device&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;User Identification&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Group Mapping Settings&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Add.Enter a unique&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Name&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to identify the group mapping configuration.Configure the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Server Profile&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;settings:Select the LDAP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Server Profile&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;you just created.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Enabled&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(default).&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I started receiving this alert&amp;nbsp;after upgrading to PAN-OS 8.0.4 and even with all lists cleared out I am still seeing this alert every 10 minutes on a PA-200. I thought, well I'm going to be upgrading those to PA-220's anyway but after researching, the limit is the same on those and even the PA-3020's I have. I am not getting alerts from the PA-3020's after upgrading those to PAN-OS 8.0.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else experienced this? Opening a ticket next week but with a lack of any search results on this error I wanted to get one posted for the next guy upgrading a PA-200 to 8.0.x. in a 'group heavy' environment.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21849"&gt;@Wald&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22073"&gt;@rkramer&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 18:46:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174224#M54759</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2017-08-31T18:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174232#M54760</link>
      <description>&lt;P&gt;So we had something similar happen while I was at ignite on our 220's however the admins that were still at the office decieded to "fix it" by adding certain groups just assuming that these boxes were too small to handle all of our groups. We have not gone back to look into it so I cannot say "exactly" the error we saw at the time. I will see if I can drum up some sort of test.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 18:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174232#M54760</guid>
      <dc:creator>Wald</dc:creator>
      <dc:date>2017-08-31T18:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174236#M54761</link>
      <description>&lt;P&gt;Here you go&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71"&gt;@bspilde&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is from a 220 running 8.0.4 code.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User Group count of 6012 exceededs threshold of 1000&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 19:14:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174236#M54761</guid>
      <dc:creator>Wald</dc:creator>
      <dc:date>2017-08-31T19:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174238#M54762</link>
      <description>&lt;P&gt;Awesome, so obviously a problem out there as far as alerts, but for how many customers is it more than just alert noise? Hmm&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 19:20:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174238#M54762</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2017-08-31T19:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174239#M54763</link>
      <description>&lt;P&gt;So, obviously those group include lists are working for you then.(?) &amp;nbsp;You received the threshold alert both before and after setting up the include list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have anything on our PA-200 that uses groups so I haven't tested whether or not things work. It seems the list of all groups exists on the firewall so I don't see how the threshold means anything regardless of list settings unless it can't see the members of those groups. I didn't go that far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll dig into local logs just to make sure the others aren't logging and not alerting on that message.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 19:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174239#M54763</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2017-08-31T19:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174240#M54764</link>
      <description>&lt;P&gt;We haven't moved ours over to the new wildcard style yet, all the groups are defined. &amp;nbsp;Working on it, just moving slowly.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 19:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174240#M54764</guid>
      <dc:creator>rkramer</dc:creator>
      <dc:date>2017-08-31T19:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174247#M54768</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71"&gt;@bspilde&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;So, obviously those group include lists are working for you then.(?) &amp;nbsp;You received the threshold alert both before and after setting up the include list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have anything on our PA-200 that uses groups so I haven't tested whether or not things work. It seems the list of all groups exists on the firewall so I don't see how the threshold means anything regardless of list settings unless it can't see the members of those groups. I didn't go that far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll dig into local logs just to make sure the others aren't logging and not alerting on that message.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71"&gt;@bspilde&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;So, obviously those group include lists are working for you then.(?) &amp;nbsp;You received the threshold alert both before and after setting up the include list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have anything on our PA-200 that uses groups so I haven't tested whether or not things work. It seems the list of all groups exists on the firewall so I don't see how the threshold means anything regardless of list settings unless it can't see the members of those groups. I didn't go that far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll dig into local logs just to make sure the others aren't logging and not alerting on that message.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The include lists work fine however this appears to be a bug as the documentation says it supports way more groups than the error.&lt;/P&gt;&lt;P&gt;We pretty much have to use include lists since we have over 6000 groups which is above and beyond the specs.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 20:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174247#M54768</guid>
      <dc:creator>Wald</dc:creator>
      <dc:date>2017-08-31T20:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174373#M54804</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21849"&gt;@Wald&lt;/a&gt; wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71"&gt;@bspilde&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;So, obviously those group include lists are working for you then.(?) &amp;nbsp;You received the threshold alert both before and after setting up the include list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have anything on our PA-200 that uses groups so I haven't tested whether or not things work. It seems the list of all groups exists on the firewall so I don't see how the threshold means anything regardless of list settings unless it can't see the members of those groups. I didn't go that far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll dig into local logs just to make sure the others aren't logging and not alerting on that message.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71"&gt;@bspilde&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;So, obviously those group include lists are working for you then.(?) &amp;nbsp;You received the threshold alert both before and after setting up the include list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have anything on our PA-200 that uses groups so I haven't tested whether or not things work. It seems the list of all groups exists on the firewall so I don't see how the threshold means anything regardless of list settings unless it can't see the members of those groups. I didn't go that far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll dig into local logs just to make sure the others aren't logging and not alerting on that message.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The include lists work fine however this appears to be a bug as the documentation says it supports way more groups than the error.&lt;/P&gt;&lt;P&gt;We pretty much have to use include lists since we have over 6000 groups which is above and beyond the specs.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Oh the alerts go away when you use "include lists" because it no longer see a large amount of groups, only the ones you have included.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:36:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/174373#M54804</guid>
      <dc:creator>Wald</dc:creator>
      <dc:date>2017-09-01T15:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/175658#M55023</link>
      <description>&lt;P&gt;I'll add to that it only sees the users for the include groups then vs all of the groups. It actually does still show 2,354 user groups from the User-ID agent.&amp;nbsp;The problem isn't really described well anywhere in my opinion. The limitation is having to store all the members of each group over 1000 groups I suspect.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 14:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/175658#M55023</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2017-09-08T14:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/200109#M59222</link>
      <description>&lt;P&gt;I had LDAP settings in a Global template, therefore all the smaller boxes that used this template alert on the group count exeeding the maximum for those models.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;To resolve this I took the most commonly used AD groups for policies and included them in the Group Include list for a Group Mapping Setting applied to a template I called Limited_Group_Capacity.&lt;/LI&gt;&lt;LI&gt;In the User Identification| Group Mapping Settings be sure to use the same name as your "Global" group used for a group mapping name.&lt;/LI&gt;&lt;LI&gt;Then include that template on top of your template stack so that it will override anything below it with the same name.&lt;/LI&gt;&lt;LI&gt;Apply that template on the top or at least above your other template containing group mappings for every stack containing models restricted to 1000 users.&lt;/LI&gt;&lt;LI&gt;Then commit and push&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 12 Feb 2018 20:25:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/system-alert-high-user-group-count-of-2358-exceededs-threshold/m-p/200109#M59222</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2018-02-12T20:25:51Z</dc:date>
    </item>
  </channel>
</rss>

