<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo stops identifying users in traffic logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181828#M56093</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Which user-id option are you using to detect the users? Agent, agentless, or wmi? I have a current case open for the User-id agents stop pulling in user data after a while and also currently the Angentless is not ablet o connect to some of my servers, another case. While its not affecting me much at the moment, it is a pain point. I'll update the case if I find out anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANOS 8.0.3 (we are upgrading to 8.0.5 to see if it helps since there seem to be a lot of fixes for the User-id agent.&lt;/P&gt;&lt;P&gt;Agent versions: 8.0.4-5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 19:41:02 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2017-10-13T19:41:02Z</dc:date>
    <item>
      <title>Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181284#M56012</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we realized that Palo Alto suddenly stops identifying users. We can see an example in this traffic logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this screenshot, we see how the user is being identified but there are connectiosn where its not appearing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sometime running show user ip-user-mapping all, we can not see the user associated to the correct ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot1.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11887iEB5BC878E5E93108/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot1.JPG" alt="Screenshot1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could it cause this problem? tshoot advice??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 12:57:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181284#M56012</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-10-11T12:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181307#M56020</link>
      <description>&lt;P&gt;how is your timeout configured on UserID?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your mappings may be timing out causing the gaps in the log, could you share your configuration?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 13:50:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181307#M56020</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-11T13:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181312#M56021</link>
      <description>&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;for similar reasons we have set ours to the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User Identification Timeout (min)&amp;nbsp; 1440&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... 24 hours and seems to be OK.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 14:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181312#M56021</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-11T14:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181573#M56063</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I wouldn't set age_out to 1440, nobody is working for 24 hours. Set the age_out time to match a users average day; so if you work from 7-5 on average then make the timeout 600 or 630 to give a little wiggle room.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 19:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181573#M56063</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-12T19:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181828#M56093</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Which user-id option are you using to detect the users? Agent, agentless, or wmi? I have a current case open for the User-id agents stop pulling in user data after a while and also currently the Angentless is not ablet o connect to some of my servers, another case. While its not affecting me much at the moment, it is a pain point. I'll update the case if I find out anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANOS 8.0.3 (we are upgrading to 8.0.5 to see if it helps since there seem to be a lot of fixes for the User-id agent.&lt;/P&gt;&lt;P&gt;Agent versions: 8.0.4-5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 19:41:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181828#M56093</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-13T19:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181882#M56096</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I'm using agents, collecting from 12 DC's. Never had an issue until updated to V8.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Agents failed to connect on occasions and when they were collecting we had a strange issue where the current policies were not allowing traffic thriugh for specific groups or users. It was a live system so had to roll back to V7 immediately. Never got chance to diagnose so please update with your findings.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 09:10:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/181882#M56096</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-14T09:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/182056#M56137</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have also seen this with my smaller deployment. We went ahead and also implemented the Agentless User-ip as as top gap since TAC was not able to find a resolution. I also made sure that I had autodiscover enabled so that it would pick up on Exchange activity. So far it is working, but some of my PAN's lose connectivity to some of my DC's, seems random but I do have a TAC case open.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I dont have a solution at the moment. Also 8.0.5 has the same issues :(.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll update when I have more information.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 17:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/182056#M56137</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-16T17:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Palo stops identifying users in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/182706#M56244</link>
      <description>&lt;P&gt;I increased the userid timeout in cache (700minutes),&amp;nbsp; now it working fine.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 07:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-stops-identifying-users-in-traffic-logs/m-p/182706#M56244</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-10-19T07:20:57Z</dc:date>
    </item>
  </channel>
</rss>

