New User-Account (__telemetryuser) with PanOS 11.2.10

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

New User-Account (__telemetryuser) with PanOS 11.2.10

L1 Bithead

Following the update to PanOS 11.2.10, a new user account will automatically be created on Panorama and the gateways:
__telemetryuser

I could not find any information about this user. What is this user used for?

2 accepted solutions

Accepted Solutions

Cyber Elite

@HeinzP,

I can just say that nothing has broken (noticeably) from removing this across a couple dozen devices. It's possible that it is preventing the collection of some new telemetry information, but it's removal hasn't caused any impact or alerting from the device itself. 

View solution in original post

L3 Networker

The user is related to the Telemetry service found in Device - Setup - Telemetry.

 

However, in our experience, while the Telemetry service is disabled, but in moving from 11.1.10-h10 to 11.1.10-h12 this user was automatically created. We have verified that Telemetry is still disabled. As we have very rigid controls and don't allow undocumented/unneeded accounts to exist, we have deleted this account with no consequences.

View solution in original post

5 REPLIES 5

L4 Transporter

hello @HeinzP 

 

users starting with the underscores are usually system accounts.

 

From the name, it is the user account used for the device telemetry.

Olivier

 

 

 

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

Cyber Elite

@HeinzP,

I either did not receive this new user in my own upgrades to 11.2.10 or I was allowed to remove it by loading a configuration file that doesn't include this user. Since I manage my devices programmatically I'm actually not positive if I just didn't get this user, or I was allowed to remove it and it isn't strictly required. Can you try just removing the user? 

I can confirm that it is possible to delete this user on the the panorama-server and on the gateways.
However, I still have no idea what this user was created for during the upgrade, or what might break if I remove it.

Cyber Elite

@HeinzP,

I can just say that nothing has broken (noticeably) from removing this across a couple dozen devices. It's possible that it is preventing the collection of some new telemetry information, but it's removal hasn't caused any impact or alerting from the device itself. 

L3 Networker

The user is related to the Telemetry service found in Device - Setup - Telemetry.

 

However, in our experience, while the Telemetry service is disabled, but in moving from 11.1.10-h10 to 11.1.10-h12 this user was automatically created. We have verified that Telemetry is still disabled. As we have very rigid controls and don't allow undocumented/unneeded accounts to exist, we have deleted this account with no consequences.

  • 2 accepted solutions
  • 5268 Views
  • 5 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!