i have a issue with the user-id feature: some users are not recognized by the PA device: if i check the logs searching for the username i see the last access some days ago, but if i search for his ip he is doing traffic.
Even checking via CLI with ' show user ip-user-mapping all | match username ' i don't see anything.
PA is running PAN-OS 7.0.7 (i know it is going to be in EOL, we will plan the upgrade).
Can you please give me some hints to check?
does "show user ip-user-mapping all" display any mappings?
Is the server monitoring status showing "connected"
have you tried "debug user-id refresh user-id ip <IP-Address> agent <User-ID Agent>" to update the PA database
if i perform "show user ip-user-mapping all" works correctly, as i told in the discussion's opening, only some users aren't recognized, not all.
DCs are shown as connected.
I will try to perform that debug command.
Are all your DCs the same version?
Is it worth searching the DC security logs to ensure user has actually registered an ip address.
could you confirm the group membership of the service account used to interrogate logs.
more “clutching at straws” really but you never know...
also... have you tried to use the windows server user-id agent.
this has pretty good dynamic logging and search capabilities.
we have 4 pointing to 12 DCs and seems to work well.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!