We experienced this issue a couple weeks ago after upgrading to User Agent 4.1.4-3. Support had us downgrade to 4.1.2-2 which resolved the issue. My understanding is that the ignore_user_list functionality had changed so that the service account login was ignored but the existing mappings were removed. Similar to you, our AV service account was being detected by Palo Alto even though it was in the Ignore list and existing users were being removed, which was functionally different from previous versions. It took us a couple days to identify the same results you were seeing.
... View more