While looking through logs to see why occionally a user gets reported as firstname.lastname@example.org instead of domain\user, we noticed the logs were filled with COMPUTERHOSTNAME@DOMAIN.COM as well. Is this expected?
@OGMaverick: Please check which user id source is providing that format
show user user-id ip-usermapping all | match <user | ip>
I guess you got the Authentication profile for that source mixed up - it's the following settings:
Auth profile is correct & the user with the computer hostname never shows in the traffic/url logs or in the CLI when I did a show user ip-user-mapping all. It's like the PCs are passing the hostname to the DCs as the username from time to time. Grabbed a small snippet of the user-ID logs to show what I'm talking about. When this happens, the user appears in traffic logs as email@example.com until they reappear into user-id the correct way. Top 2 are normal and have the username. Second two are showing PC hostname. All from the same source. Would love to stop the bottom 2 from happening
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The LIVEcommunity thanks you for your participation!