<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows User-ID agent not collecting mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410619#M92618</link>
    <description>&lt;P&gt;Went over that document already.&amp;nbsp; Nothing missed as far as I can tell.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jun 2021 15:57:44 GMT</pubDate>
    <dc:creator>LucasCroce</dc:creator>
    <dc:date>2021-06-02T15:57:44Z</dc:date>
    <item>
      <title>Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410608#M92615</link>
      <description>&lt;P&gt;I'm working on getting a Windows User-ID agent set up for a customer and it's not collecting logs.&amp;nbsp; Checked all permisssions and service account user is in Event Log Readers and has permissions to both the install folder and registry entries.&amp;nbsp; Just as a test, I had the customer add the service account to the domain admins group and the user mapping started populating immediately.&amp;nbsp; Any permissions that I'm missing?&amp;nbsp; If not, what could be wrong on the AD side preventing Event Log Readers from viewing the logs?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410608#M92615</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T15:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410613#M92616</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check out this article. My guess is something might have been missed/overlooked?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Once thing we found that worked better for us were using the Exchange logs instead. Outlook is always hitting Exchange and authenticating, so if a user moves their laptop or goes wireless, its a faster transition on the firewall side of things.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:54:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410613#M92616</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-02T15:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410619#M92618</link>
      <description>&lt;P&gt;Went over that document already.&amp;nbsp; Nothing missed as far as I can tell.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:57:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410619#M92618</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T15:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410624#M92621</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is the service that is running the user-id agent set to run as the user/service account you setup to allow it grab logs from a DC?&lt;/P&gt;
&lt;P&gt;Just grasping at straws, but it seems as an authentication/authorization issue.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:23:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410624#M92621</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-02T16:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410630#M92623</link>
      <description>&lt;P&gt;You mean is the user configured in the user-id agent the same one in the "event log readers" group? Yes.&amp;nbsp; The user configured in the agent has been added to the group, is permitted to log on as a service, has rights to the PAN folder under Program Files (x86), and has rights to the PAN registry entries listed.&amp;nbsp; Like I said originally, all permissions and groups and things associated with the service account user were double and triple checked.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: You are absolutely right though that this is an authorization issue because like I said adding the same user to Domain Admins makes it work.&amp;nbsp; I've done dozens of user-id installs before and this is the first time I've had it not work when all documented permissions where in place.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410630#M92623</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T16:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410635#M92625</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sorry for not making myself clear, I meant the windows service:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1622651695952.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34199i8F3D5BBACD06256E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1622651695952.png" alt="OtakarKlier_0-1622651695952.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If that doesnt work, I'd say open a support case since you already went through everything.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410635#M92625</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-06-02T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410640#M92626</link>
      <description>&lt;P&gt;Oh, I'll double check that but I'm pretty sure that is the case as the agent stops and starts correctly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410640#M92626</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T16:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410641#M92627</link>
      <description>&lt;P&gt;doesn't this account require access to the security logs and not the event logs?&amp;nbsp; or did i misread here...?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:41:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410641#M92627</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-02T16:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410644#M92628</link>
      <description>&lt;P&gt;Misread I think.&amp;nbsp; I was talking about adding the user to the "event log readers" group as mentioned in documentation.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410644#M92628</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T16:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410647#M92629</link>
      <description>&lt;P&gt;on the AD side have you matched this criteria..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Must be a member of Event Log Readers, Server Operators, and Distributed COM.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 17:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410647#M92629</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-02T17:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410648#M92630</link>
      <description>&lt;P&gt;Yes, the user is in those groups.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 17:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410648#M92630</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T17:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410649#M92631</link>
      <description>&lt;P&gt;Hmm odd,,, i will double check mine in the morning as we have 4 agents hammering away nicely on both windoze servers and local.&lt;/P&gt;&lt;P&gt;are your agents on servers or local....????&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 17:16:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410649#M92631</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-02T17:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410650#M92632</link>
      <description>&lt;P&gt;Agents installed on Windows Servers.&amp;nbsp; They connect to the firewall fine.&amp;nbsp; Services start and stop fine.&amp;nbsp; DCs are populated in the interface.&amp;nbsp; Just no user mappings.&amp;nbsp; I think I'll recommend this customer contact TAC.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 17:18:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410650#M92632</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-02T17:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410791#M92645</link>
      <description>&lt;P&gt;OK just FYI,,,&amp;nbsp; we had to add add user rights "Manage auditing and security log" to the service account for this to work but cant remember exactly why as it was a while ago...&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 09:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410791#M92645</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-03T09:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410852#M92655</link>
      <description>&lt;P&gt;You mean under "User Rights Assignment" in group policy?&amp;nbsp; I already thought of that and tried it.&amp;nbsp; It didn't appear to work.&amp;nbsp; Customer opened a case yesterday.&amp;nbsp; We'll see what support says.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 12:15:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/410852#M92655</guid>
      <dc:creator>LucasCroce</dc:creator>
      <dc:date>2021-06-03T12:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID agent not collecting mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/574115#M115405</link>
      <description>&lt;P&gt;Adding to an old thread due to Google search results.&amp;nbsp; My solution was someone had enabled an advanced audit policy in the default domain controllers GPO, which in turn disables the basic audit policies.&amp;nbsp; I followed&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/audit-policy-recommendations" target="_blank"&gt;https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/audit-policy-recommendations&lt;/A&gt;&amp;nbsp;to enable the recommended audit settings, ran gpupdate on all DCs, and the User-ID agent started pulling logs from the DCs again.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 16:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-not-collecting-mapping/m-p/574115#M115405</guid>
      <dc:creator>RyanAugustine</dc:creator>
      <dc:date>2024-01-23T16:44:14Z</dc:date>
    </item>
  </channel>
</rss>

