Source Users don't show up in Traffic & Threat

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Source Users don't show up in Traffic & Threat

L1 Bithead

My problem is the Source User in Monitor > Logs > Traffic & Threat don't show for all users.  All other columns including Source and Destination IP are displayed properly.  The unshown users can be from trusted lan/wlan/vpn zones and is going to trusted lan or untrusted wan zones.  The application they run can be ssl, facebook or dns...  

 

The f/w model is PA-3020, ver 7.0.10.   Windows User-ID-Agent is ver. 8.0.2-20, implemented on a domain server and running and connected to 2 domain controllers.  All configs for the part of Windows User-ID Agent in this post (https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321) are checked and confirmed.  Our desktops are most Win 7 and a few MACs.  All laptops are Win 7 with a few Surface Pro running Win 10.  

 

Anyone has an idea what configs are missed?

5 REPLIES 5

L1 Bithead

forgot to mention, all users computers have an older version 2.x GlobalProtect installed and run on startup. 

Did you check the "destination user" column in the threat log? Is this column also empty in your logs?

 

The reason that in threat log your users are probably shown as destination users is because when paloalto blocks a threat or an exploit on a website the source of the attack is not your internal user. In this case your user is the destination user. Or even better in case of threats it is not dst and src users, it is attacker and victim.

-->

  • Sourceuser = attacker
  • Destinationuser = victim

Thanks for your clarification.  It's my fault mixing up the names in 2 different logs.  In Threat log, the Victim column shows IP without problems but a few attackers (from internal trusted zones) don't show their names in Attacker Name column.

 

Compared to the Threat log, Traffic log has a lot more unshown names.

But this means you have at least some usernames in your logs? Did you try to find out which user you see: win7, macos, win10? May be this would help to find the root cause of the problem.
In the user id agent logs: do you have user-ip-mappings there?
You mentionned that you have GP installed on ALL computers. This is already probably the best setup which theroretically makes the use of user id agent obsolete. (But I would recommend updating the GP clients to a newer version)

Yes.  I do have I guess >50% usernames shown in Traffic log.  The ones don't show are Win 7 or Mac OS desktops (I haven't checked the Win 10 yet because only a few Surf Pro have Win 10 installed).  

 

The User-ID Agents is connected (green dot) and running.  The usernames from the installed Agent program matches those shown in Traffic log, but the number of actual connected users are much more.  

 

My colleague tried to push the newer version of GP through fw to all client machines but failed so we stay with the old one before we test it out.  I was thinking the same but it doesn't make sense why the desktops are affected.  Desktops don't have GP installed and connect to the internal network with CAT 5e.  

 

Thanks for your suggestions.  I will try updating GP and maybe it'd help with some of the usernames display issue.

  • 3150 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!