User-ID not mapping all traffic

Reply
Highlighted
L4 Transporter

User-ID not mapping all traffic

Why the user-id is missing for some traffic. This also causes issue with policies using user-id. 

Below traffic log is for same user/zone/ip

image.png

Highlighted
L2 Linker

Re: User-ID not mapping all traffic

How is your User-ID mapping implementation configured?

Highlighted
L4 Transporter

Re: User-ID not mapping all traffic

@staustin We have agent-less configuration to pull user-ID's from domain controllers

Highlighted
L4 Transporter

Re: User-ID not mapping all traffic

Can anyone suggest what the issue might be.
Highlighted
L7 Applicator

Re: User-ID not mapping all traffic

You might have the timeout set too low. Default is 45 mins.  I have mine set to 24 hours.  Some suggest 8 is OK but it depends on domain activity.  

Highlighted
L4 Transporter

Re: User-ID not mapping all traffic

@MickBall We have it for 15 hours and even if it was 45mins that would not explain why within matter of minutes there is username associated for some traffic while not for other.

Highlighted
L7 Applicator

Re: User-ID not mapping all traffic

Yes i can now see that in your original post. How many servers are you monitoring. Could it be that one of them is not reading the security logs correctly and overwriting the correct information.

Highlighted
Cyber Elite

Re: User-ID not mapping all traffic

Hello,

If you are using exchange, I would suggest checking against it. The reason is that when Outlook is open it is authenticating very frequently.

 

Regards,

Highlighted
L4 Transporter

Re: User-ID not mapping all traffic

@MickBall and @OtakarKlier Thanks for suggestions. But how would i check/determine if some server is not reading security logs correctly. We are using 3 of them. Also there is no exchange server, its O365 that we have. 

 

I did install agent on 1 of them and it seems better, but i will monitor and update

Highlighted
L7 Applicator

Re: User-ID not mapping all traffic

To test this i would remove 2 servers from user id and see what happens, then add a second, monitor, then add the third.... it should not cause any issues as you seem not to be using id’s for policies. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!