<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261125#M74023</link>
    <description>&lt;P&gt;are you using local users or are you going through an authentication protocol (kerberos, ldap, ...) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;locally created users will show up in the configuration log and is not part of the reporting capabilities (as these are traffic oriented)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you export system logs a SIEM might be able to craft a nice report&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2019 13:23:12 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-05-15T13:23:12Z</dc:date>
    <item>
      <title>Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261054#M74005</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;How can i extract a detailed report on the list of all Global protect users (VPN users). this report aims to get the date each user was created. this is for audit reasons and i would appreciate if any one has a solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 07:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261054#M74005</guid>
      <dc:creator>Abduba</dc:creator>
      <dc:date>2019-05-15T07:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261122#M74020</link>
      <description>&lt;P&gt;There are multiple ways to get this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are just doing it one time, you can look at the system logs and use the following search filter&lt;/P&gt;&lt;P&gt;(eventid eq globalprotectportal-config-succ).&amp;nbsp; This could take a really long time depending on how long you keep logs for some might want to also add a date filter like&amp;nbsp;(receive_time in last-30-days).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can use the API using the following&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;https://"Firewall URL"/api/?type=op&amp;amp;cmd=&amp;lt;show&amp;gt;&amp;lt;global-protect-gateway&amp;gt;&amp;lt;previous-user/&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;&amp;lt;/global-protect-gateway&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 15 May 2019 13:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261122#M74020</guid>
      <dc:creator>dpeterson4</dc:creator>
      <dc:date>2019-05-15T13:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261125#M74023</link>
      <description>&lt;P&gt;are you using local users or are you going through an authentication protocol (kerberos, ldap, ...) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;locally created users will show up in the configuration log and is not part of the reporting capabilities (as these are traffic oriented)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you export system logs a SIEM might be able to craft a nice report&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 13:23:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect/m-p/261125#M74023</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-15T13:23:12Z</dc:date>
    </item>
  </channel>
</rss>

