<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Server Monitoring Not Connected in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257956#M73183</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft AD under Server Monitoring is showing as 'not connected.'&lt;/P&gt;&lt;P&gt;We would like to use the PAN-OS Integrated User-ID Agent&lt;/P&gt;&lt;P&gt;Output from debug commands show UserID Debug Log is enabled but nothing is logging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone encountered similar issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2019 09:58:48 GMT</pubDate>
    <dc:creator>FarzanaMustafa</dc:creator>
    <dc:date>2019-04-18T09:58:48Z</dc:date>
    <item>
      <title>Server Monitoring Not Connected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257956#M73183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft AD under Server Monitoring is showing as 'not connected.'&lt;/P&gt;&lt;P&gt;We would like to use the PAN-OS Integrated User-ID Agent&lt;/P&gt;&lt;P&gt;Output from debug commands show UserID Debug Log is enabled but nothing is logging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone encountered similar issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 09:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257956#M73183</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-04-18T09:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Server Monitoring Not Connected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257980#M73189</link>
      <description>&lt;P&gt;did you follow this guide?:&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 11:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257980#M73189</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-04-18T11:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Server Monitoring Not Connected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257982#M73191</link>
      <description>Yes, but still no luck.</description>
      <pubDate>Thu, 18 Apr 2019 11:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/257982#M73191</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-04-18T11:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Server Monitoring Not Connected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/261187#M74043</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you find the solution for this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 16:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/261187#M74043</guid>
      <dc:creator>upatino</dc:creator>
      <dc:date>2019-05-15T16:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Server Monitoring Not Connected</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/261276#M74074</link>
      <description>&lt;P&gt;Yes...PA TAC assisted us in resolving the issue. Below is the case notes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; less mp-log useridd.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking at User-ID logs, there were repeated logs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2019-04-23 12:36:36.704 +1000 Error: pan_user_id_win_log_query(pan_user_id_win.c:1364): log query for sydcwdc01.mainstreambpo.local failed: NTSTATUS: NT code 0x80041003 - NT code 0x80041003&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2019-04-23 12:36:36.704 +1000 Error: pan_user_id_win_get_error_status(pan_user_id_win.c:1055): WMIC message from server sydcwdc01.mainstreambpo.local: NTSTATUS: NT code 0x80041003 - NT code 0x80041003&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;WMI error code 0x80041003 indicates the account does not have permission.&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://docs.microsoft.com/en-gb/windows/desktop/WmiSdk/wmi-error-constants" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-gb/windows/desktop/WmiSdk/wmi-error-constants&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please check that the service account (mainstreambpo\palocw) is member of Event Log Readers and Distributed COM Users&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Some useful commands related to User-ID:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Restart User-ID service: debug software restart process user-id&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- View server monitor statistics: show user server-monitor statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other than the group membership of service account, kindly also check the WMI permission in every DC server being used under Server Monitoring. This WMI permission is local configuration (not replicated).&lt;BR /&gt;&lt;BR /&gt;Agentless User-ID 'Access Denied' Error In Server Monitor&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clk0CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clk0CAC&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We checked that we have given all the correct permissions on the WMI side for all our DCs.&amp;nbsp;&lt;BR /&gt;We asked for a trace to run to figure out what exactly its failing on when it accesses the AD side of things.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PA TAC provided us the following.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Provided that the WMI permissions are set, can you test to do WMI remote connection using wbemtest?&lt;BR /&gt;1. In any windows client (domain member), run wbemtest&lt;BR /&gt;2. Default namespace is 'root\cimv2', please change to '\\&amp;lt;dcservername&amp;gt;\root\cimv2'&lt;BR /&gt;3. Provide username and password (firewall service account), then click Connect&lt;BR /&gt;4. Observe if there is error message when wbemtest is trying to connect to DC server&lt;BR /&gt;&lt;BR /&gt;Link:&amp;nbsp;&lt;A href="https://blogs.technet.microsoft.com/configmgrdogs/2014/08/20/test-your-collection-wql-queries-using-wbemtest-and-powershell/" target="_blank" rel="noopener"&gt;https://blogs.technet.microsoft.com/configmgrdogs/2014/08/20/test-your-collection-wql-queries-using-wbemtest-and-powershell/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This fixed the issue!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 23:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-not-connected/m-p/261276#M74074</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-05-15T23:29:04Z</dc:date>
    </item>
  </channel>
</rss>

