I have an open ticket with Palo Alto for our 5020 series and User-ID problems. My organization has been using PA for years and we never had issues with the User-ID portion until after moving into version 8 (it would seem). Support hasnt been much help for this question, so I want to figure out what your doing for this.
I have our User-ID agent on 3 DC's (2012) and is scraping all our other servers. The problem were having is that nearly all our user rules are based on active directory group association or username based. So the username is the key. Lately the identification is posing major challenges as its flopping between the actual user account logged in and the computer account.
In the firewall were picking up Computer names from AD (with the $ preceding), which from my understanding in the past this was ignored via the User-ID / Firewall.
How are you dealing with the detection of computernames$ being present in the security logs for logon/logoff events and getting User-ID agents or the firewall to ignore the $ named logons, I have attempted doing exclusions but this is not working.
Thanks in advance!
Solved! Go to Solution.
Did you install User-ID Agent 8.1.0 recently? If yes, then update to version 8.1.1 and the problem is gone.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!