<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source User is empty in Monitor tab in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239284#M68518</link>
    <description>&lt;P&gt;firstly I would take a note of one of the source IP's.&lt;/P&gt;&lt;P&gt;then run a filter on just that source ip to see if any user has ever been observed with that address...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if so then check your user mapping timeouts. they may be too low.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your timeout is set to 45 mins and no AD activity in that time then user to ip will be removed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are you using the device/user mapping or user-id agent.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2018 13:03:27 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-11-09T13:03:27Z</dc:date>
    <item>
      <title>Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239276#M68516</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes the "Source User" column is empty.&amp;nbsp;What should I check in the settings&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN version 8.0.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 12:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239276#M68516</guid>
      <dc:creator>BethSouza</dc:creator>
      <dc:date>2018-11-09T12:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239284#M68518</link>
      <description>&lt;P&gt;firstly I would take a note of one of the source IP's.&lt;/P&gt;&lt;P&gt;then run a filter on just that source ip to see if any user has ever been observed with that address...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if so then check your user mapping timeouts. they may be too low.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your timeout is set to 45 mins and no AD activity in that time then user to ip will be removed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are you using the device/user mapping or user-id agent.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 13:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239284#M68518</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-09T13:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239295#M68521</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34403"&gt;@mi&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The timeout is set to 10 minutes. I had to reduce because of another problem.&lt;/P&gt;&lt;P&gt;I applied the filter as you recommended, but no user was shown to the ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using the user-id agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 15:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239295#M68521</guid>
      <dc:creator>BethSouza</dc:creator>
      <dc:date>2018-11-09T15:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239297#M68522</link>
      <description>&lt;P&gt;increase the timeout on the user id agent to 4 hours it will be all good&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 15:20:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239297#M68522</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-09T15:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239299#M68524</link>
      <description>&lt;P&gt;i dont think reducing the timeout resolved your other problem....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;suggests 4 hours. this is a good suggestion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have mine set to 8 hours but 4 should suffice providing the PC has some domain activity within that 4 hours.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 15:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239299#M68524</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-09T15:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239300#M68525</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101107"&gt;@BethSouza&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you are looking to keep the low ageout value you'll want to monitor something that has a bit more logs for the firewall to pull users from, such as Exchange.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 15:41:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239300#M68525</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-09T15:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239421#M68562</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;not to hijack but is there a list of sources that can be used for UserID?&amp;nbsp; I knew of a few, including AD of course, but we ended up setting our timeouts to indefinate as that seemed to be the answer for domain joined machines that might have users that stay logged in to (I just lock mine everyday for example).&amp;nbsp; The UserID for that IP would then only clear if the user logged off the machine.. although I'm assuming we may end up with stale data due to IP address changes.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Nov 2018 03:15:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239421#M68562</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-11-11T03:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239513#M68585</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39461"&gt;@jsalmans&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That would work depending on your environment and your security requirements, but wouldn't generally be recommended due to the fact that the UserID information isn't likely to be accurate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sources that I know of are the following:&lt;/P&gt;&lt;P&gt;- Active Directory&lt;/P&gt;&lt;P&gt;- Exchange Server&lt;/P&gt;&lt;P&gt;- eDirectory Servers&lt;/P&gt;&lt;P&gt;- Syslog Servers&lt;/P&gt;&lt;P&gt;- Terminal Servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really since you have the ability to get syslog information and import information with the API, you can technically get user-id information from pretty much anything. For example the Cisco ISE and Cisco WLCs easily through this method.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 15:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239513#M68585</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-12T15:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Source User is empty in Monitor tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239517#M68589</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were running into an issue where the User IDs were timing out and we'd start to see inconsistent logging... some logs would have the UserID, some wouldn't, then some would again.&amp;nbsp; Obviously this would make UserID security based policy very difficult.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our wireless and ResNet areas (basically all BYOD) use SafeConnect for NAC and we're already using their implementation to update Palo Alto UserID (they recommend an API user account be created for SafeConnect to use).&amp;nbsp; We had to change the default timeout here because users on these networks only have to log in devices once every 120 days right now.&amp;nbsp; Since they are BYOD, these devices don't usually change users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The remainder of our network is academic and office spaces.&amp;nbsp; For academic areas, lab computers and teacher workstations are logged in and out for class periods.&amp;nbsp; Assuming a logoff event triggers a UserID clear event through the user agent connected to the AD controllers, UserID should be fairly up-to-date here.&amp;nbsp; If not, the next user logging in should update it.&amp;nbsp; For the office areas, I believe we had a lot of people leaving their computers logged in and just locked when they weren't around (I'm included here).&amp;nbsp; I don't believe an unlock generates an AD security event so UserID here was eventually expiring on the Palo Alto and not populating.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 16:11:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-is-empty-in-monitor-tab/m-p/239517#M68589</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-11-12T16:11:54Z</dc:date>
    </item>
  </channel>
</rss>

