Intermittent UserID - Syslog Parser -

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Intermittent UserID - Syslog Parser -

L2 Linker

Anyone see this behavior? we are using syslog parser string for userid, no logout action, timeout set to 45 minutes ( default). You can see here that a flow within the same second shows a userid and then blank with same source address. FW running 10.2.7 h-8 . Any ideas? 

 

NSutfin_0-1723726668467.png

 

-Nathan
1 accepted solution

Accepted Solutions

What this actually was (cut out of screenshot), was that the loss of user-id was between different device-groups within a network. As a user was moving through the network encountering several different firewalls, not all firewalls had been set up for user-id. The search that was being used was against the whole group of firewalls using the user ip address.

-Nathan

View solution in original post

2 REPLIES 2

Hi @NSutfin ,

Note that traffic logs are generated at the end of the session. Although the logs are generated few seconds apart, the actuall session for each log may have started minutes apart.

 

Try the following:

- Check the session start timestamp for two logs one with user-id and one without

- Check the user-ID logs to see the timestamp when the user-to-ip mapping was created

- Verify the mapping timeout has not expired for the two session start timestamps

 

What this actually was (cut out of screenshot), was that the loss of user-id was between different device-groups within a network. As a user was moving through the network encountering several different firewalls, not all firewalls had been set up for user-id. The search that was being used was against the whole group of firewalls using the user ip address.

-Nathan
  • 1 accepted solution
  • 428 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!