Agent Users
Agent users connect through GlobalProtect or Prisma Access Agent. Select the
number under Agent Users to view details about your agent
users.
View details about your
Users,
User
Devices, and the number of currently connected users. You can
View Trend by Users or
User
Devices connected to
Prisma Access at the time indicated in
the timestamp. From the
Scope Selection drop-down, select
All,
Prisma Access, or
NGFW users to refine the data that appears. If you
have an
Autonomous DEM (ADEM) license, you can
remove
NGFW from the drop-down to view ADEM-related
data.
Baselines in Widgets
If you purchased the AI-Powered ADEM license, you see a baseline data band
across the trend widgets on the following Monitor pages: Users, Branch Sites,
Data Centers, and Network Services. The widgets show the baseline in the
background across the trend lines. This allows you to view at a glance whether
your data has crossed the upper or lower boundaries of the baseline.
Baseline data is calculated in 1-hour bin sizes and takes into consideration the
last 28 days of data from those hour-long bins for a particular tunnel, site,
Prisma Access location, or GlobalProtect user count. For example, the
baseline from 1:00 pm to 2:00 pm on Tuesday is calculated from the 1:00 pm to
2:00 pm time frame on the previous four Tuesdays. The lower bound is the 10th
percentile of that historical data collected, and the upper bound is its 90th
percentile. This allows you to see trends for bandwidth, user counts,
authentication counts, and DNS Proxy request and response. Because the baseline
data is taken from the last 28 days of historical data, the newly onboarded
tenants will need to be up and data rich for 28 days for the baseline to be
calculated correctly. If your data is less than 28 days, you may see some
discrepancies.
When the values in the trend line in the widget deviate from the baseline's upper
or lower limits, the trend line for that period appears in red in the web
interface.
The following example shows the GlobalProtect baseline from the
Connected User widget on the Users page.
Access Agent Users Graph
Hover over the trend line in the Access Agent Users
chart to observe the number of Connected Users or
Connected User Devices and the corresponding
connection time.
Monitored Users
If you have an AI-Powered ADEM license, you can view the number of
users monitored by Autonomous DEM (ADEM) and the number of monitored user
devices. This widget appears only when you have disabled
NGFW from the Scope
Selection drop-down.
- Monitored Users—Total number of users monitored
by ADEM.
- Average User Experience Score—Experience score
aggregated across all users monitored on ADEM. See how many users have a
Good (green), Fair (orange), or Poor (red) experience score.
- Monitored User Devices—Total number of user
devices monitored by ADEM.
Agent Risky Users
View the number of agent users affected by threats. The Up or Down arrow
compares this time range with a previous time range to determine the
difference, in percentage, of the number of connected devices.
View More Details for Access Agent Versions
Select View More Details for:
Access Agent Versions shows the access agent
versions that your users’ devices are using to connect to Prisma Access. Select GlobalProtect or
Prisma Access Agent to see the total
Number of Connected Devices based on the
agent versions during the last 30 days. Use the data displayed to
enforce compliance with the latest GlobalProtect
or Prisma Access Agent versions. Expand the arrow to see the count of
connected devices per agent subversions.
The GlobalProtect agent subversions are
displayed for devices connected to Prisma Access only.
View More Details for IP Pool Utilization
Static IP pools provide an alternate
means of allocating IP addresses to the agent users. To view
IP pool utilization by different IP pool allocation theaters based on
the number of connected users at that time, select
View More
Details for:
IP Pool Utilization. The IP pool utilization
percentage on the graph is the number of IP pool blocks used out of all
the IP pool blocks that are available across all the subnets. You can
proactively add subnets when you see an IP pool bar approaching the
maximum capacity for any region.
IP Pool Utilization Details
Current IP Pool Utilization—One IP pool
address block is a /24 subnet and has 254 IP addresses. Allocation
of a pool block counts toward utilization; however, allocating a
pool block does not mean that all IP addresses are in use. There are
still available pool blocks that can be allocated to new or existing
mobile user gateways as needed. You can view IP pool utilization per
pool locations and subpool regions.
IP Pool Allocation—The IP pool
utilization percentage on the graph is the number of IP pool
blocks used out of all the IP pool blocks that are available
across all subnets. You can add subnets when you see an IP
pool bar approaching the maximum capacity for any
region.
- Static IP Address Allocation provides an
alternate means of allocating IPs to the agent users.
IP Pool Details shows IP pool
utilization displayed under the IP Pool
Name that comes from the static IP pool
configuration. Total IP Pool Profiles
shows the number of utilized profiles in the IP pool, and
Total Unused IP Addresses shows the
number of unused IP addresses in the IP pool.
The
IP Pool Details table
shows:
- IP Pool Name—Unique IP pool name.
- Total IP Addresses—Total number
of users in the IP pool.
- Active IP Addresses—Total number
of active users in the IP pool.
- Peak Utilization Status—Highest
percentage of use for the IP pool during the selected
Time Range.
- Last IP Assignment Timestamp—Most
recent time the IP pool was active.
Access Agent Users Table
The Access Agent Users table shows
Users or User
Devices.
Users
- Current Connected—Turn Current
Connected
ON to view connected users only. Turn it
OFF to see all of your users.
- User Name—Unique username.
- User Devices—Number of devices associated
with the user.
- Applications—Number of applications
connected to the user.
- Threats—Threats information for the
user.
- Data Usage—User's data usage.
- Last Login Time—Last date and time the
user logged in.
User Devices
- Current Connected—Turn Current
Connected
ON to view connected users only. Turn it
OFF to see all of your users.
- Agent Type—Filter information by
GlobalProtect or Prisma Access Agent.
- Source IP Address—Unique IP address.
- OS Family/Version—OS family and version
to which the device belongs.
- User Experience Score—Overall application
experience score of your users.
- Last Device Location—Device's location by
city, country.
- Last Firewall/PA Location—Last connected
NGFW name or Prisma Access location.
- ISP Name—Unique ISP name.
- Last Activity Time—Most recent date and
time the user was active.
- Connectivity
Mode—Tunnel,
Proxy, or Tunnel and
Proxy.
- Self Serve Notifications—(ADEM only)
Number of Self-Serve notifications sent to the user's
device.
- Self Serve Status—(ADEM only) Enabled or
disabled on the device.
Click on any username to view information about the user's
Activity,
Connectivity, and
Experience.
Agent User Activity
See the user's Total Threats,
Threats by Risk Level, Unique
Threats, Web Browsing
Summary, and Application Summary
during the selected time range.
Unique Threats provides details about the
threats this user faced during the time range selected.
The
Web Browsing Summary shows details about
the URLs the user has visited.
- Overview shows the number of unique
URLs that the user has visited, Severity of
URLs (High,
Medium, or
Low), and the number of
Malicious URLs the user has
visited.
Most Visited Sites shows
the most visited sites in order of number of times
visited, Site Category,
Risk Level, and number of
Sessions, or visits the user
made to this site.
- Blocked shows the number of
Blocked URLs the user tried to
access, the Severity of Blocked URLs
(High,
Medium, or
Low), Malicious
Blocked URLs, and Blocked URLS
with Most Visited Sites.
- Sessions shows:
- Total Hits—The number of
times the user has accessed websites.
- Category Session
Breakdown—Breaks down the types of sites
the user visited.
- Top URL Categories for
Sessions—The top categories, in order,
that the user visited.
- Data Transfer shows the
Total Data Transferred,
Category Data Transfer Breakdown,
and Top URL Categories for Data
Transfer table that shows
Category, Unique
URLs for each category, and Data
Transferred, in MB, for each category.
Application Summary shows information about
the user's applications during the selected time range.
- Activity—The user's number of
Total Apps, Applications
by Risk Score, Top App
Categories, and a list of All
Applications that shows each one's
App Risk score. App risk scores are
ranked in numerical order from high (5) to low (0).
- Blocked—The user's Total
Blocked Applications, Total Allowed
Applications, and the Total Blocked
Applications table that shows a list of blocked
applications by Application Name and
Rule.
- Sessions—Details about each time the user
accessed each application. You can view the user's number of
Total Sessions, Category
Sessions Breakdown, and the Top Used
Applications, which shows the number of user
sessions for each application during the selected time
range.
- Data Transfer—The Total Data
Transferred, Category Data Transfer
Breakdown, and Top Applications with
Data Transferred by Application
Name and Data Transferred
in MB.
Click one of the icons
from this page or from to download, share, and schedule reports for user
activity with details shown on this page.
Agent User Connectivity
Understand your user's device connectivity by reviewing the
Connected User's Device Trend chart,
Connected User's Devices, and
User Login & Logout Events on all
devices.
Click one of the icons
from this page to
download, share, and schedule reports with user connectivity
details shown on this page.