<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Group Count Exceeds threshold in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216259#M62654</link>
    <description>&lt;P&gt;Hi the user-ID agent does not collect group information, it only forwards user + ip, groups are collected through the firewalls "group mapping settings"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you add the 31 groups to the "group include list"?&lt;/P&gt;
&lt;P&gt;maybe the full set was fetched somehow vefore you completed your configuration, you could try this command to clear out the excess:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id clear group all
&amp;gt; debug user-id refresh group-mapping all &lt;/PRE&gt;</description>
    <pubDate>Fri, 01 Jun 2018 12:55:16 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-06-01T12:55:16Z</dc:date>
    <item>
      <title>User Group Count Exceeds threshold</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216227#M62646</link>
      <description>&lt;P&gt;Recently upgraded to 8.0.9 from 7.1.x with mutiple devices from PA200 up to PA3050, Using UserIdAgent against an MS domain. managed via Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Started getting notifications in thes system log along the lines of 'User Group count of 7492 exceededs threshold of 1000'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In UserId -&amp;gt; GroupMapping I have an LDAP search filter that returns only the groups that are relevant to the firewall, 31 in total, &amp;amp; I can see thats correct via "show user group-mapping statistics" so Im guessing that the 7,492 referes to the user-group-mapping information returned from the UserIdAgent in total, ie for all our users there are 7,492 unqiue groups at the moment. I dont appear to be able to filter the information returned by UserIdAgent to just the groups that the firewall needs to know about.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question is should I be worried - I dont seem to have a problem with the user mapping for the 31 groups of interest on the firewall but I would like to get rid of the alert from the logs + there is a certain amount of information leakage in that firewall administrators can see users full group membership from AD via "show user user-ids match-user" when really they should only be concerned with the 31 groups that control firewall permissions.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 08:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216227#M62646</guid>
      <dc:creator>SimmSimm</dc:creator>
      <dc:date>2018-06-01T08:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count Exceeds threshold</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216259#M62654</link>
      <description>&lt;P&gt;Hi the user-ID agent does not collect group information, it only forwards user + ip, groups are collected through the firewalls "group mapping settings"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you add the 31 groups to the "group include list"?&lt;/P&gt;
&lt;P&gt;maybe the full set was fetched somehow vefore you completed your configuration, you could try this command to clear out the excess:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id clear group all
&amp;gt; debug user-id refresh group-mapping all &lt;/PRE&gt;</description>
      <pubDate>Fri, 01 Jun 2018 12:55:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216259#M62654</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-01T12:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count Exceeds threshold</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216261#M62657</link>
      <description>&lt;P&gt;Interesting !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having a spare system to play with, I tried that &amp;amp; it does appear to clear out all the other groups ! thanks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its not clear to me how they all got there in the first place - but looking at one of our new 820s which started life on PanOs 8, they only have the&amp;nbsp; 31 groups I would expect whilst the older boxes which have been upgrading from the days of 5.x have the full 7,576 so Im guessing you are right - at some point in the past the LDAP lookup has retrieved the whole lot &amp;amp; its never been cleared out since.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nick.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 13:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/216261#M62657</guid>
      <dc:creator>SimmSimm</dc:creator>
      <dc:date>2018-06-01T13:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: User Group Count Exceeds threshold</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/309735#M80239</link>
      <description>&lt;P&gt;Hello to everyone ,&lt;/P&gt;&lt;P&gt;I ran the debug user-id clear group all command.&lt;/P&gt;&lt;P&gt;I get the following error.&lt;BR /&gt;Server error: op command for client useridd timed out as client is not available&lt;/P&gt;&lt;P&gt;Model PA-850&lt;BR /&gt;Software Version 9.0.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;( eventid eq user-group-count ) and ( description contains 'User Group count of 1072 exceeds threshold of 1000' )&lt;/P&gt;&lt;P&gt;Best Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 10:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-count-exceeds-threshold/m-p/309735#M80239</guid>
      <dc:creator>ozayoz</dc:creator>
      <dc:date>2020-02-06T10:00:38Z</dc:date>
    </item>
  </channel>
</rss>

