Hello, I have developed a script that collects user-ip mapping from a wireless controller and send this info to User-ID Agent. All these looks fine because I can see the users in the User-ID Agent monitor table, but when I look traffic logs on Palo Alto I can see some logs do not have a user identification and other logs have it, for the same source IP. I attach a screenshot where you can see what I am trying to explain :smileysilly:. The user-ip mapping is correctly catched by PaloAlto. admin@PA-500> show user ip-user-mapping ip 172.21.8.195 IP address: 172.21.8.195 User: alumnes\zwillis Ident. By: AD Idle Timeout: 3581s Max. TTL: 3581s Groups that the user belongs to (used in policy) Does anyone knows what could be happening? Cheers,
... View more