<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230457#M95509</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to use the the DAGPusher prototype but, unhappily, I'm dealing with some problems. May be some of you could help me with it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;My scenario:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use a generic miner to extract IPv4 (/32) from a specific location (that is working). Then it is sent to the DAGPusher node (that is working). Now I want to push them to Firewall/Panorama (it is not working).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;My configuration:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my local DAGPusher prototype, I use the configuration showed in figure 1 (green arrow). You can see that I only set the "tag_prefix":"agencias" parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The status tab (figure 3) in the node cloned from this prototype, I have the indicators been received. Fine! And the Handled_Device tab show the Firewall destination (figure 2). Although I have multiplus devices and manage all of them through Panorama I choose to test DAGPusher with only one of them, at first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitoring the traffic log I&amp;nbsp;can see that my MM VM is trying to communicate with the device, and this traffic is allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Panorama I created a shared DAG with only one match: 'agencias' (figure 3).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Status/Questions:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point my DAG is not populated. Through the CLI, using the command "show object registered-ip all" I got nothing.&lt;BR /&gt;Could you guys identify something wrong? The syntax and the tags I used are corrects?&lt;BR /&gt;The fact that I created a shared DAG in Panorama could be the problem? Can I populate a shared DAG only in one Firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advanced.&lt;BR /&gt;Best regards.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Sep 2018 17:41:56 GMT</pubDate>
    <dc:creator>danilo.souza</dc:creator>
    <dc:date>2018-09-11T17:41:56Z</dc:date>
    <item>
      <title>Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230457#M95509</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to use the the DAGPusher prototype but, unhappily, I'm dealing with some problems. May be some of you could help me with it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;My scenario:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use a generic miner to extract IPv4 (/32) from a specific location (that is working). Then it is sent to the DAGPusher node (that is working). Now I want to push them to Firewall/Panorama (it is not working).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;My configuration:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my local DAGPusher prototype, I use the configuration showed in figure 1 (green arrow). You can see that I only set the "tag_prefix":"agencias" parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The status tab (figure 3) in the node cloned from this prototype, I have the indicators been received. Fine! And the Handled_Device tab show the Firewall destination (figure 2). Although I have multiplus devices and manage all of them through Panorama I choose to test DAGPusher with only one of them, at first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitoring the traffic log I&amp;nbsp;can see that my MM VM is trying to communicate with the device, and this traffic is allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Panorama I created a shared DAG with only one match: 'agencias' (figure 3).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Status/Questions:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point my DAG is not populated. Through the CLI, using the command "show object registered-ip all" I got nothing.&lt;BR /&gt;Could you guys identify something wrong? The syntax and the tags I used are corrects?&lt;BR /&gt;The fact that I created a shared DAG in Panorama could be the problem? Can I populate a shared DAG only in one Firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advanced.&lt;BR /&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 17:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230457#M95509</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-11T17:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230577#M95510</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to share some information and ask one more question. In the figure attached, you can see that my MM is pushing data to the Firewall (traffic log). My question is: EDLs have a specific interface to be received (DEVICE -&amp;gt; SERVICES -&amp;gt; SERVICES ROUTE CONFIGURATION). How about DAGs? Do the API in DAGpusher have to send the data to a specific interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 12:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230577#M95510</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-12T12:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230843#M95511</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11678"&gt;@lmori&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you help me with this issue. I believe&amp;nbsp;the problem is in my local miner, specifically the way the "tag" is attached to the indicator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My shared DAG in Panorama is prepared to match 'mm_loc_agencias'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My local DAGPusher has, now, this configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;==============&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; "tag_prefix": "mm_",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; "tag_watermark": "pushed",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; "tag_attributes": "loc"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;==============&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My local miner is from the class "&lt;SPAN&gt;minemeld.ft.http.HttpFT". I've tried out three configurations so far and none of them successfully. The basic configuration is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;==============&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;age_out:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; default: null&lt;BR /&gt;&amp;nbsp; &amp;nbsp; sudden_death: true&lt;BR /&gt;attributes:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; confidence: 95&lt;BR /&gt;&amp;nbsp; &amp;nbsp; share_level: green&lt;BR /&gt;&amp;nbsp; &amp;nbsp; type: IPv4&lt;BR /&gt;&amp;nbsp; &amp;nbsp; interval: 300&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;tag:&lt;/FONT&gt;&lt;BR /&gt;indicator:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; regex: ([0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})&lt;BR /&gt;&amp;nbsp; &amp;nbsp; transform: \1&lt;BR /&gt;verify_cert: false&lt;BR /&gt;source_name: xxx_log&lt;BR /&gt;url: http://xxx/static/log.txt&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In &lt;FONT color="#FF0000"&gt;tag&lt;/FONT&gt; I've tried:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;tag:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "loc": "agencias"&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;tag:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; loc: "agencias"&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;tag: agencias&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would really appreciate any help. I've read the "Poor man's NAC Application" article, but there, you use a localDB node to feed the DAGPusher. In my case I use a local miner, and the way the attributes are attached to indicator are different.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you in advanced.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 12:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230843#M95511</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-14T12:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230936#M95512</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79020"&gt;@danilo.souza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access to PANOS API is not controlled with service route configurations but:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The user/password you're using might have a RBAC policy denying access to the API (user-id)&lt;/LI&gt;
&lt;LI&gt;You could be using VSYS (although it is supported you must provide it into the prototype)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 14 Sep 2018 22:06:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230936#M95512</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-14T22:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230940#M95513</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your reply. Almost&amp;nbsp;sure the credential&amp;nbsp;used has the privilege to access the API. I will double check it as soon as possible.&amp;nbsp;To be frank, I am most concerned with the sintaxe and tags used in the Miner and DAGPusher.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm that the way I explicity the "tag" (at least one of the three ways I've tried out) atribute in my Miner is correct? Will it, togheter with the "tag_prefix" (mm_) in DAGPusher, match the 'mm_loc_agencias' criteria that I put in the shared DAG? I'm not sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm that is possible to populate a shared DAG (created in Panorama) just in one Firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 23:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230940#M95513</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-14T23:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230950#M95514</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79020"&gt;@danilo.souza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regardless of your miner and output node configurations, any IPv4/32 indicator reaching (Update message) the DAGOutput node should register the IP using the pre-defined watermark tag. But you report that the command "show object registered-ip all" does not return anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is what is making me believe that either the user does not have access to the API or you're using VSYS and a csutom configuration is required.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Sep 2018 07:53:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/230950#M95514</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-15T07:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231059#M95515</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I double checked the credentials and I can confirm that the user used to push the IPs to the DAG has the correct permissions. Could you tell me wich specific procedures should I follow in case I have a VSYS ( only one, named vsys1, with default configurations)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 13:51:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231059#M95515</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-17T13:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231487#M95516</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This customization that you&amp;nbsp;said (dealing with a VSYS), is something similar the hacking we apply when using an api key (DAGPusher file configuration)? The same way you mentioned in the "&lt;SPAN&gt;Using MineMeld to implement a poor man's NAC application (DAGPusher)&lt;/SPAN&gt;" article? I couldn't find any information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 14:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231487#M95516</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-19T14:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231573#M95517</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79020"&gt;@danilo.souza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;probably is time to troubleshoot the PANOS device. Palo Alto Networks TAC team can support you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I'd do is to turn on debug messages for user-is ip registration events:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;admin@VM-Series&amp;gt; debug user-id set userid regip
admin@VM-Series&amp;gt; debug user-id on debug&lt;/PRE&gt;
&lt;P&gt;And then tail the useridd.log file&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;admin@VM-Series&amp;gt; tail follow yes mp-log useridd.log &lt;/PRE&gt;
&lt;P&gt;A typical successfull registration of an IP would generate a log track record like the following one&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;2018-09-19 22:53:01.330 -0700 debug: cfgagent_opcmd_callback(pan_cfgagent.c:468): useridd: cfg agent received op command from server
2018-09-19 22:53:01.331 -0700 debug: cfgagent_doop_callback(pan_cfgagent.c:503): received signal to execute for agent: useridd
2018-09-19 22:53:01.336 -0700 debug: pan_regip_add_ip(pan_reg_ip.c:1080): add registered ip 172.16.214.200 in vsys 1
2018-09-19 22:53:01.340 -0700 debug: pan_regip_reg(pan_reg_ip.c:1186): &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;reg ip 172.16.214.200 with tag WebAppServer&lt;/FONT&gt;&lt;/STRONG&gt; in vsys 1
2018-09-19 22:53:01.978 -0700 Processing dnld delta : 1, full : 2
2018-09-19 22:53:01.982 -0700 debug: pan_regip_notify_modified(pan_reg_ip.c:3153): regip-modified notified to other daemons as: incremental change
2018-09-19 22:53:01.982 -0700 dnld 1 registered ip takes 0 seconds&lt;/PRE&gt;
&lt;P&gt;And, a typical unregistration like this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;2018-09-19 22:53:44.620 -0700 debug: cfgagent_opcmd_callback(pan_cfgagent.c:468): useridd: cfg agent received op command from server
2018-09-19 22:53:44.621 -0700 debug: cfgagent_doop_callback(pan_cfgagent.c:503): received signal to execute for agent: useridd
2018-09-19 22:53:44.621 -0700 debug: pan_regip_obj_remove_tag(pan_reg_ip.c:1027): unregister ip 172.16.214.200 in vsys 12018-09-19 22:53:44.621 -0700
debug: pan_regip_unreg(pan_reg_ip.c:1365): &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;unreg ip 172.16.214.200 with tag WebAppServer&lt;/STRONG&gt;&lt;/FONT&gt; in vsys 1
2018-09-19 22:53:44.621 -0700 debug: pan_regip_unreg(pan_reg_ip.c:1410): remove registered ip 172.16.214.200 in vsys 1 since no tags associated with i
t any more&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Sep 2018 06:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231573#M95517</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-20T06:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231629#M95518</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I have to backtrack when I said I had the correct credentials. At first, I used a key generated for a active "super user" because I was just testing DAGPusher and didn't want to create a new user. Everything I&amp;nbsp;reported in previous posts were related with this user. To eliminate any doubt I tried to push the IP to Firewall by myself using the line below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------&lt;/P&gt;&lt;P&gt;curl -F key=LUFRPT0&lt;FONT color="#FF0000"&gt;-----------&lt;/FONT&gt;kJQbm9qTT0 --form file=@/home/user/ips.xml "https://firewall/api/?type=user-id"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But I got this answer:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;response status = 'error' code = '403'&amp;gt;&amp;lt;result&amp;gt;&amp;lt;msg&amp;gt;Invalid credentials.&amp;lt;/msg&amp;gt;&amp;lt;/result&amp;gt;&amp;lt;/response&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So I created a new user (now, not a "super user", but a "panorama administrator" (PANORAMA) and "device administrator" (FIREWALL)) and submit the previous line with the new key:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;curl -F key=LUFRPT1&lt;FONT color="#FF0000"&gt;-----------&lt;/FONT&gt;sc21JVT0&amp;nbsp;--form file=@/home/user/ips.xml "https://firewall/api/?type=user-id"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;and I got the same answer:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;response status = 'error' code = '403'&amp;gt;&amp;lt;result&amp;gt;&amp;lt;msg&amp;gt;Invalid credentials.&amp;lt;/msg&amp;gt;&amp;lt;/result&amp;gt;&amp;lt;/response&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Both usear are capable of create DAG, adresses (Objects) etc. and commit these changes.&amp;nbsp;Does it make any sense?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 14:45:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231629#M95518</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-20T14:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231719#M95519</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79020"&gt;@danilo.souza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible that you're targetting a Panorama instead of a PANOS device to push User-ID REGISTER messages?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama does not implemente the User-ID API. That is a PANOS only feature. You can use Panorama as an API Gateway to reach the PANOS Device API. But, in any case, the REGISTER/UNREGISTER messages generated by the DAG Pusher output node must be targetted to a PANOS Device (or to a list of devices)&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 10:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231719#M95519</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-21T10:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231733#M95520</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I'm not targeting Panorama. I created the shared DAG in Panorama, but I'm pushing the IP to a specific Firewall. I used the command below (from the MM machine) to generate the key (for both users).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----------------&lt;/P&gt;&lt;P&gt;curl -k -X GET 'https://&lt;FONT color="#FF0000"&gt;firewall&lt;/FONT&gt;/api/?type=keygen&amp;amp;user=&lt;FONT color="#FF0000"&gt;user&lt;/FONT&gt;&amp;amp;password=&lt;FONT color="#FF0000"&gt;xxxxxxx&lt;/FONT&gt;'&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After your comment, I check out if Panorama would generate a different api key (for both users), so I repeated the proccess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----------------&lt;/P&gt;&lt;P&gt;curl -k -X GET 'https://&lt;FONT color="#FF0000"&gt;panorama&lt;/FONT&gt;/api/?type=keygen&amp;amp;user=&lt;FONT color="#FF0000"&gt;user&lt;/FONT&gt;&amp;amp;password=&lt;FONT color="#FF0000"&gt;xxxxxxx&lt;/FONT&gt;'&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the same keys. So the keys are double checked.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 12:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231733#M95520</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-21T12:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231891#M95521</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79020"&gt;@danilo.souza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm afraid you'll have to sort out the access to the UserID entry point in the PANOS Device API with Palo Alto Networks TAC before trying to deploy the DAG Pusher node in MineMeld&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 08:00:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/231891#M95521</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-22T08:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/232537#M95522</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a ticket at PaloAlto and resolved the problem with the api key ("Invalid Credentials").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inicially, I generated my keys through a Curl command from the MM machine. With the PaloAlto support, I used the browser and can confirm that the keys are barely different. I don't want speculate but I think my problem was an issue with Curl when generating my keys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Later, I can detail the&amp;nbsp;procedure followed to generate the new keys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, the problem is not resolved yet. I can't populate my DAG using the DAGPusher, but I can do that manually. In the figure below you can see that I uploaded two IPs. To do that, I used (in the browser ) the line below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;https://PANORAMA/api/?key=LUFRPT04OG---------VkJQbm9qTT0=&amp;amp;cmd=&amp;lt;uid-message&amp;gt;&amp;lt;version&amp;gt;2.0&amp;lt;/version&amp;gt;&amp;lt;type&amp;gt;update&amp;lt;/type&amp;gt;&amp;lt;payload&amp;gt;&amp;lt;register&amp;gt;&amp;lt;entry ip="152.XXX.XXX.121"&amp;gt;&amp;lt;tag&amp;gt;&amp;lt;member&amp;gt;mm_loc_agencias&amp;lt;/member&amp;gt;&amp;lt;/tag&amp;gt;&amp;lt;/entry&amp;gt;&amp;lt;/register&amp;gt;&amp;lt;/payload&amp;gt;&amp;lt;/uid-message&amp;gt;&amp;amp;type=user-id&amp;amp;target=FIREWALL_SERIAL_NUMBER&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DAG populated" style="width: 594px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16795i491616748F2B3CEA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="show_object_registered_.png" alt="DAG populated" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;DAG populated&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the same user (login/password, not api key) in MM, I can't see new IPs populating my DAG. My indicator in the DAGPusher node is showed in the figure below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Indicator in DAGPusher" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16797i4EFDA6CE33326386/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Captura_log_DAGPusher_.png" alt="Indicator in DAGPusher" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Indicator in DAGPusher&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am using the tag prefix "mm_" in DAGPusher and the miner attachs the tag "loc_agencias" to the indicator. My DAG is prepared to match "mm_loc_agencias".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you visualize any error in the precedures/parameters I am following/setting in my configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:32:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/232537#M95522</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-26T19:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/232648#M95523</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79020"&gt;@danilo.souza&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you go back to message &lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Dynamic-Address-Group-DAG-PAN-OS-DAGPusher-prototype/m-p/231573/highlight/true#M2558" target="_self"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Dynamic-Address-Group-DAG-PAN-OS-DAGPusher-prototype/m-p/231573/highlight/true#M2558&lt;/A&gt; and execute the debug commants shown there to troubleshoot the UserID API from PANOS' foint of view?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 07:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/232648#M95523</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2018-09-27T07:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/232699#M95524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6710"&gt;@xhoms&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I executed the procedure, but you explicited lines with a successful registration and unregistration IP. Wich&amp;nbsp;logs should I observe to get the details of a failed attempt to&amp;nbsp;&lt;SPAN&gt;register an IP?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 13:52:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/232699#M95524</guid>
      <dc:creator>danilo.souza</dc:creator>
      <dc:date>2018-09-27T13:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Address Group (DAG) PAN-OS / DAGPusher prototype</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/367261#M95525</link>
      <description>&lt;P&gt;The solution is to create "tags" that associate to the vsys under the address group. This is created in each vsys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmora_0-1607074750176.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28960i1FD8109554971741/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmora_0-1607074750176.png" alt="jmora_0-1607074750176.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmora_1-1607074806192.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28961i01252183E086D3E8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmora_1-1607074806192.png" alt="jmora_1-1607074806192.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 09:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-address-group-dag-pan-os-dagpusher-prototype/m-p/367261#M95525</guid>
      <dc:creator>jmora</dc:creator>
      <dc:date>2020-12-04T09:46:54Z</dc:date>
    </item>
  </channel>
</rss>

