Reports based on groups

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Reports based on groups

L6 Presenter


When we try to get custom reports by typing a query for source user(domain\group) and run now, it gets empty.when we type user name it is working.

Any idea ?



L5 Sessionator

Try following query :

(user.src in 'cn=home,cn=users,dc=amb,dc=local')

OR (user.src in 'amb\home')

we already tried both but report comes empty.

Can you query traffic logs  using query in above formats?

for users yes we can query with domain\user

L3 Networker


The log format in 3.x is

domain, receive_time, serial, type, subtype, config_ver, time_generated, src, dst, natsrc, natdst, rule, srcuser, dstuser, app, vsys, from, to, inbound_if, outbound_if, logset, time_received,

sessionid, repeatcnt, sport, dport, natsport, natdport, flags, proto, action, bytes, bytes_sent, bytes_received, packets, start, elapsed, category, padding

If the record of the group is not written to the traffic log, i suppose it is an expected behavior that the queries based on groups will return empty.

I may be wrong since its 3.x panos.



Try this :

> show user ip-user-mapping ip <ip of the user which shows up in traffic Logs>

Use the Group in the Group(s) field for the query in the traffic logs  :  (user.src in 'Group in the Group(s) field')

Thanks.We did that.

Still reports come empty for gorups.


Is PAN firewall retrieving the user-group information properly?

>show user group name <group name>  //this should list all the group members of the group

>show user user-IDs match user <username> //shows the groups a user is a part of.

If the firewall is able to identify the users in the group and see traffic logs for these users, it should match the query for the report.



  • 8 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!