<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID ignore multiple users - agentless or agent in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9617#M7045</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got an installation with approx 70k+ users, where user-id is an important factor. I want to ignore all user with prefix adm or svc in the user name(admin and service accounts) from user-id, to avoid getting unwanted ip-user-mappings. I have the option to both use agentless and agent on windows server. There are so many admin and service accounts, that adding one by one in a txt file or in the cli on the fw simply isn't an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've searched a lot for this both in articles here and the admin guides, but I can't find a good solution. Does anybody have a smart way to solve this issue? I.e. scripting or something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input would be appreciated, as this is really becoming a pain...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Mar 2015 13:12:46 GMT</pubDate>
    <dc:creator>torm</dc:creator>
    <dc:date>2015-03-10T13:12:46Z</dc:date>
    <item>
      <title>User-ID ignore multiple users - agentless or agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9617#M7045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got an installation with approx 70k+ users, where user-id is an important factor. I want to ignore all user with prefix adm or svc in the user name(admin and service accounts) from user-id, to avoid getting unwanted ip-user-mappings. I have the option to both use agentless and agent on windows server. There are so many admin and service accounts, that adding one by one in a txt file or in the cli on the fw simply isn't an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've searched a lot for this both in articles here and the admin guides, but I can't find a good solution. Does anybody have a smart way to solve this issue? I.e. scripting or something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input would be appreciated, as this is really becoming a pain...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2015 13:12:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9617#M7045</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2015-03-10T13:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID ignore multiple users - agentless or agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9618#M7046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The LDAP search string for this is quite easy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;"(&amp;amp;(objectCategory=person)(objectClass=user)(!cn=adm*)&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;(!cn=svc*)&lt;/SPAN&gt;)"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;This filter can be used under User Identification -&amp;gt; Group Mapping -&amp;gt; Server Profile -&amp;gt; User objects&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;The User-ID Best Practice guide also says:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;"The Group Include List can then be used to filter which groups from the LDAP servers are displayed in the Firewall Policy Interface. This also filters which users are tracked in the firewall logs. If a user does not belong to one of these groups, the firewall will not record the users name in the various logs."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/previewBody/6591-102-5-22672/User-ID_Best_Practices-6.pdf" style="font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;" title="https://live.paloaltonetworks.com/servlet/JiveServlet/previewBody/6591-102-5-22672/User-ID_Best_Practices-6.pdf"&gt;https://live.paloaltonetworks.com/servlet/JiveServlet/previewBody/6591-102-5-22672/User-ID_Best_Practices-6.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;Is this helpful for you?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;Regards,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; font-size: 13px;"&gt;- Kim&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2015 13:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9618#M7046</guid>
      <dc:creator>Kim_Hansen</dc:creator>
      <dc:date>2015-03-10T13:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID ignore multiple users - agentless or agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9619#M7047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nice to know, but it's unfortunately not what I'm looking for. This would help in narrowing down the ldap part of user-id (group-mapping), but not the IP-user-mapping part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need a way to filter away ip-user-mappings containing a prefix(i.e. adm or svc). Using the ignore_user_list.txt in agent or "set user-id-collector ignore-user" in agentless does not scale in a large environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2015 13:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9619#M7047</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2015-03-10T13:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID ignore multiple users - agentless or agent</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9620#M7048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can try using a tool like powershell and save the output in a text file (be careful with that amount of users can impact the server performance)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://windowsitpro.com/systems-management/find-users-get-aduser" title="http://windowsitpro.com/systems-management/find-users-get-aduser"&gt;Find Users with Get-ADUser | Systems Management content from Windows IT Pro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After checking the correct name format you just rename the file 'ignore_user_list.txt' and put it in the Installation agent folder. This can be a workaround, because of your many users this could impact the User agent performance (better to run it in a dedicated server) and also I couldn't find the maximum excluded users the file can contain.&lt;/P&gt;&lt;P&gt;I advise you to contact your SE to create a feature request to filter out user to IP mapping based on wildcards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Aug 2015 16:15:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ignore-multiple-users-agentless-or-agent/m-p/9620#M7048</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2015-08-07T16:15:41Z</dc:date>
    </item>
  </channel>
</rss>

