what is destination user field in traffic and threat logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

what is destination user field in traffic and threat logs

L4 Transporter

I can see destination user field in traffic and threat logs getting poulated.

How this data is collected.

 

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com
1 REPLY 1

Cyber Elite
Cyber Elite

The same as source user, through user-IP mapping

 

If a user is identified by UserID (agent, captive portal ,....) a user-ip mapping is created on the firewall, anything coming from- or going to that IP can then be matched to the currently active user.

 

This could come in handy when for example a patch management system pushes updates out to your clients, you'll see which user was associated to the IP at the time the patch was sent out

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 3363 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!