Thanks for the reply. I am planning on using the Captive Portal as the second option; however, my plan is to use a wireless controller(Rukus) to monitor the syslog event logs and extract the usernames and IP addresses. I got a bit confused by the instructions in the link below as it says "Determine whether there is a pre-defined syslog filter for your particular syslog sender(s). Palo Alto Networks provides several pre-defined syslog filters, which are delivered as Application content updates and are therefore updated dynamically as new filters are developed. The pre-defined filters are global to the firewall, whereas manually defined filters apply to a single virtual system only." We don't have a virtual system. Does that mean that I will not be able to create a manual filter for the WLC we have which is Rucks WLC if we don't have a virtual system? https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/user-id-features/user-id-integration-with-syslog#_50964 Best, ~zK
... View more