<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user activity ACC -CLI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/208882#M61106</link>
    <description>&lt;P&gt;(receive_time geq '2018/04/05 14:30:00') AND (receive_time leq '2018/04/05 15:15:00') AND ((srcuser eq '')) AND ((dstuser eq ''))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you filter your traffic logs with that query it will display the logs that actually make up that traffic during the time period that you have displayed in your screenshot.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2018 13:57:38 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-04-05T13:57:38Z</dc:date>
    <item>
      <title>user activity ACC -CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/208873#M61104</link>
      <description>&lt;P&gt;Dears&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to know the IP of this user "None",as&amp;nbsp;per to&amp;nbsp;a below&amp;nbsp;image,&amp;nbsp;through CLI ...Can I do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please feedback with the command or the way to know who it is ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="User Activity Log.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14639iDD52E10CB885EE68/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="User Activity Log.png" alt="User Activity Log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 13:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/208873#M61104</guid>
      <dc:creator>AhmedEmam</dc:creator>
      <dc:date>2018-04-05T13:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: user activity ACC -CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/208882#M61106</link>
      <description>&lt;P&gt;(receive_time geq '2018/04/05 14:30:00') AND (receive_time leq '2018/04/05 15:15:00') AND ((srcuser eq '')) AND ((dstuser eq ''))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you filter your traffic logs with that query it will display the logs that actually make up that traffic during the time period that you have displayed in your screenshot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 13:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/208882#M61106</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-05T13:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: user activity ACC -CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/209152#M61159</link>
      <description>&lt;P&gt;Thank you to your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this filter no give us the source IP which is mentioned by "None" .&lt;BR /&gt;I need to determine the "user activity " by specefic command to know that&lt;/P&gt;</description>
      <pubDate>Sun, 08 Apr 2018 10:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/209152#M61159</guid>
      <dc:creator>AhmedEmam</dc:creator>
      <dc:date>2018-04-08T10:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: user activity ACC -CLI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/209325#M61210</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84509"&gt;@AhmedEmam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That command will give you all of the traffic that would have matched the screenshot you provided in your original post. But let me try again with a little more of a description.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) There is no one source IP that would be granted the source-user None. This source-user ID is applied to all traffic that traverses your firewall that does not have a user-mapping associated with it. This could be caused by a user-id age-out being met, or it could be that the source truly doesn't have anything that would match to a user-id (ex: Printers).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) The command provided eariler was specific to your prior example and provides a timeframe of a query that would need to be run on the traffic logs. It was not an example of a full cli command to do so; you would need to incorporate it into your command to view the traffic logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) There is a button on the right of that display that will be 'Jump to logs' that will bring you right to the logs that the ACC is reading to generate the display.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4)&lt;/P&gt;&lt;P&gt;The CLI to view log files is the following:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show log traffic&lt;/PRE&gt;&lt;P&gt;You would then need to actually set the query, for example&lt;/P&gt;&lt;PRE&gt;show log traffic query equal ' ((srcuser eq "")) and ((dstuser eq "")) '&lt;/PRE&gt;&lt;P&gt;That query typed in directly would provide you any log that was matching what the ACC was viewing to get the statistic originally displayed without the time restriction.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 21:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-activity-acc-cli/m-p/209325#M61210</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-09T21:18:32Z</dc:date>
    </item>
  </channel>
</rss>

