<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Agent installed on Domain Controller doesn't appear to be collecting event logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213549#M62108</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've installed the Palo User-ID agent on a single domain controller (8.0.906) using the Palo Networks guide below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent" target="_self"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our environment already has User-ID running and is working, but due to some server retirement we have had to change the placement of this application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I installed the application, gave the dedicated domain service account full control over the Palo User-ID application folder, full control over the registry keys in Wow6432Node (ensured child object permissions for both were replaced) and the service account is already a member of the required AD builtin groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've then added the new server to firewall and confirmed it is connected (change commited).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the logs under Monitoring does not show any activity for user ID collections, the old (existing) server is still pulling them out OK. The only entries I am seeing are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;need to alloc xxxx bytes for big body&lt;/PRE&gt;&lt;P&gt;I understand this one is normal and can be ignored (&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/quot-Warn-839-quot-message-seen-in-User-ID-agent-logs/ta-p/104091" target="_self"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/quot-Warn-839-quot-message-seen-in-User-ID-agent-logs/ta-p/104091&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;New connection 127.0.0.1 : 61332
Device thread 0 with 127.0.0.1 : 61332 is started.
Device thread 0 accept finish.&lt;/PRE&gt;&lt;P&gt;Which I assume is it connecting to itself (domain controller) OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;can't get prefix from address()&lt;/PRE&gt;&lt;P&gt;I then see this event a lot, I've modified the include/exclude address ranges (192.168.0.0/16) on the Discovery option but I can't get this to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 May 2018 09:11:30 GMT</pubDate>
    <dc:creator>Wildman85</dc:creator>
    <dc:date>2018-05-08T09:11:30Z</dc:date>
    <item>
      <title>User-ID Agent installed on Domain Controller doesn't appear to be collecting event logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213549#M62108</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've installed the Palo User-ID agent on a single domain controller (8.0.906) using the Palo Networks guide below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent" target="_self"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our environment already has User-ID running and is working, but due to some server retirement we have had to change the placement of this application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I installed the application, gave the dedicated domain service account full control over the Palo User-ID application folder, full control over the registry keys in Wow6432Node (ensured child object permissions for both were replaced) and the service account is already a member of the required AD builtin groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've then added the new server to firewall and confirmed it is connected (change commited).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the logs under Monitoring does not show any activity for user ID collections, the old (existing) server is still pulling them out OK. The only entries I am seeing are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;need to alloc xxxx bytes for big body&lt;/PRE&gt;&lt;P&gt;I understand this one is normal and can be ignored (&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/quot-Warn-839-quot-message-seen-in-User-ID-agent-logs/ta-p/104091" target="_self"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/quot-Warn-839-quot-message-seen-in-User-ID-agent-logs/ta-p/104091&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;New connection 127.0.0.1 : 61332
Device thread 0 with 127.0.0.1 : 61332 is started.
Device thread 0 accept finish.&lt;/PRE&gt;&lt;P&gt;Which I assume is it connecting to itself (domain controller) OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;can't get prefix from address()&lt;/PRE&gt;&lt;P&gt;I then see this event a lot, I've modified the include/exclude address ranges (192.168.0.0/16) on the Discovery option but I can't get this to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 09:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213549#M62108</guid>
      <dc:creator>Wildman85</dc:creator>
      <dc:date>2018-05-08T09:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent installed on Domain Controller doesn't appear to be collecting event logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213557#M62109</link>
      <description>&lt;P&gt;Only difference I can see is that my working server is using 7.0.713 instead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Installed 8.0.906 on a member server and that has the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;can't get prefix from address()&lt;/PRE&gt;</description>
      <pubDate>Tue, 08 May 2018 10:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213557#M62109</guid>
      <dc:creator>Wildman85</dc:creator>
      <dc:date>2018-05-08T10:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent installed on Domain Controller doesn't appear to be collecting event logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213558#M62110</link>
      <description>&lt;P&gt;Installing 7.0.7-13 works. So I'll stick with that one I guess. Would be to know why the newer version(s) are causing that error.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 11:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-installed-on-domain-controller-doesn-t-appear-to/m-p/213558#M62110</guid>
      <dc:creator>Wildman85</dc:creator>
      <dc:date>2018-05-08T11:09:59Z</dc:date>
    </item>
  </channel>
</rss>

