<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic user-id in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254835#M72330</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running PA local user-id agent in PAN os 8.1.3&lt;/P&gt;&lt;P&gt;i am facing an issue that my server monitoring is shows as 'not-connected', i am able to test the authentication and proper service account is configured. it was working fine for long time and hope ther was some windows patch in AD server recently.&lt;/P&gt;&lt;P&gt;when i capture in AD server, i am able to see communocation between firewall and server, when firewall queries for tree, windows server is replying the LDAP tree as well.&lt;/P&gt;&lt;P&gt;i am not sure how PA reads the security log and get IP-USER mapping, so not able to check the same.&lt;/P&gt;&lt;P&gt;in PA user-id logs, i am able to see the following error,&lt;/P&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;&amp;lt;var/log/pan/useridd.log&amp;gt; 2019-03-24 17:47:52.517 +0400 Error: pan_user_id_win_log_query(pan_user_id_win.c:1364): log query for EOHODC01 failed: NTSTATUS: NT code 0xc002001b - NT code 0xc002001b&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;&amp;lt;var/log/pan/useridd.log&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;&amp;lt;var/log/pan/useridd.log&amp;gt; 2019-03-24 17:47:52.517 +0400 Error: pan_user_id_win_get_error_status(pan_user_id_win.c:1055): WMIC message from server EOHODC01: NTSTATUS: NT code 0xc002001b - NT code 0xc002001b&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;Does anybody knows what is this error is ?.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Sun, 24 Mar 2019 20:36:04 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2019-03-24T20:36:04Z</dc:date>
    <item>
      <title>user-id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254835#M72330</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running PA local user-id agent in PAN os 8.1.3&lt;/P&gt;&lt;P&gt;i am facing an issue that my server monitoring is shows as 'not-connected', i am able to test the authentication and proper service account is configured. it was working fine for long time and hope ther was some windows patch in AD server recently.&lt;/P&gt;&lt;P&gt;when i capture in AD server, i am able to see communocation between firewall and server, when firewall queries for tree, windows server is replying the LDAP tree as well.&lt;/P&gt;&lt;P&gt;i am not sure how PA reads the security log and get IP-USER mapping, so not able to check the same.&lt;/P&gt;&lt;P&gt;in PA user-id logs, i am able to see the following error,&lt;/P&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;&amp;lt;var/log/pan/useridd.log&amp;gt; 2019-03-24 17:47:52.517 +0400 Error: pan_user_id_win_log_query(pan_user_id_win.c:1364): log query for EOHODC01 failed: NTSTATUS: NT code 0xc002001b - NT code 0xc002001b&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;&amp;lt;var/log/pan/useridd.log&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;&amp;lt;var/log/pan/useridd.log&amp;gt; 2019-03-24 17:47:52.517 +0400 Error: pan_user_id_win_get_error_status(pan_user_id_win.c:1055): WMIC message from server EOHODC01: NTSTATUS: NT code 0xc002001b - NT code 0xc002001b&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&lt;SPAN class="ng-binding"&gt;Does anybody knows what is this error is ?.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="ng-scope"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sun, 24 Mar 2019 20:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254835#M72330</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-03-24T20:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: user-id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254842#M72331</link>
      <description>&lt;P&gt;&lt;SPAN class="ng-binding"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp; , guys pleas advice if you have any inputs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 20:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254842#M72331</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-03-24T20:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: user-id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254856#M72338</link>
      <description>&lt;P&gt;have you checked out these articles:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFWCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFWCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agentless User-ID requires a useraccount that's set up for WMI to be able to read logs, while authentication and directory tree are ldap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 06:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/254856#M72338</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-03-25T06:52:29Z</dc:date>
    </item>
  </channel>
</rss>

