<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple PA-500 with PanOS 8.0.4, some SYSTEM ALERT: high : User Group count exceeds threshold o in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-pa-500-with-panos-8-0-4-some-system-alert-high-user/m-p/177614#M55372</link>
    <description>&lt;P&gt;&lt;SPAN&gt;VM-50, VM-100, VM-300, PA-200, PA-220, PA-500, PA-800 Series, PA-3020, and PA-3050 firewalls are all restricted to 1,000 AD groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Basically means you can't have more than a 1000 groups imported from AD into the PAN-OS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2017 14:41:21 GMT</pubDate>
    <dc:creator>RichColeman</dc:creator>
    <dc:date>2017-09-19T14:41:21Z</dc:date>
    <item>
      <title>Multiple PA-500 with PanOS 8.0.4, some SYSTEM ALERT: high : User Group count exceeds threshold of 1k</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-pa-500-with-panos-8-0-4-some-system-alert-high-user/m-p/176879#M55247</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The company&amp;nbsp;have many PA-500 in HA configuration across the globe, configured by the U.S. team. After upgrade to PanOS 8.0.4, 2 of them are sending alerts like "&lt;STRONG&gt;SYSTEM ALERT : high : User Group count of 16##&amp;nbsp;exceededs threshold of 1000&lt;/STRONG&gt;", each of different country and small difference in user group count.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the "Group Mapping Settings", it's using the LDAP Lookup method for the &lt;STRONG&gt;User Identification&lt;/STRONG&gt;. It's the same config with another one that doesn't send Alerts. So I am a bit confused what to do to stop that 2 sending Alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone experienced same issue - same hardware, same OS version, same config but&amp;nbsp;few&amp;nbsp;gives Alert? I have seen&amp;nbsp;&lt;A title="SYSTEM ALERT : high : User Group count of 2358 exceededs threshold of 1000" href="https://live.paloaltonetworks.com/t5/General-Topics/SYSTEM-ALERT-high-User-Group-count-of-2358-exceededs-threshold/m-p/174373#M54804" target="_self"&gt;https://live.paloaltonetworks.com/t5/General-Topics/SYSTEM-ALERT-high-User-Group-count-of-2358-exceededs-threshold/m-p/174373#M54804&lt;/A&gt;&amp;nbsp;but we are with different&amp;nbsp;environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Email&amp;nbsp;body from Alert&lt;/U&gt;:&lt;/P&gt;&lt;PRE&gt;domain: 1
receive_time: 2017/09/18 10:26:50
serial:&amp;nbsp;x_redacted_x
seqno: 210806
actionflags: 0x8000000000000000
type: SYSTEM
subtype: userid
config_ver: 0
time_generated: 2017/09/18 10:26:50
dg_hier_level_1: 0
dg_hier_level_2: 0
dg_hier_level_3: 0
dg_hier_level_4: 0
vsys_name: 
device_name:&amp;nbsp;x_redacted_x
vsys_id: 0
vsys: 
eventid: user-group-count
object: 
fmt: 0
id: 0
module: general
severity: high
opaque: User Group count of 1662 exceededs threshold of 1000&lt;/PRE&gt;&lt;P&gt;By the way, why is it "&lt;EM&gt;exceededs&lt;/EM&gt;"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any suggestions.&lt;/P&gt;&lt;P&gt;Patrick.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 00:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-pa-500-with-panos-8-0-4-some-system-alert-high-user/m-p/176879#M55247</guid>
      <dc:creator>PK-GHL</dc:creator>
      <dc:date>2017-09-18T00:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple PA-500 with PanOS 8.0.4, some SYSTEM ALERT: high : User Group count exceeds threshold o</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-pa-500-with-panos-8-0-4-some-system-alert-high-user/m-p/177614#M55372</link>
      <description>&lt;P&gt;&lt;SPAN&gt;VM-50, VM-100, VM-300, PA-200, PA-220, PA-500, PA-800 Series, PA-3020, and PA-3050 firewalls are all restricted to 1,000 AD groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Basically means you can't have more than a 1000 groups imported from AD into the PAN-OS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2017 14:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-pa-500-with-panos-8-0-4-some-system-alert-high-user/m-p/177614#M55372</guid>
      <dc:creator>RichColeman</dc:creator>
      <dc:date>2017-09-19T14:41:21Z</dc:date>
    </item>
  </channel>
</rss>

